Radio
Now Playing
Quickyla Radio โ€” Click to play
Open โ†’
3 min left
Back to News

AI coding tools increase dependency sprawl, raising malware risks for developers

AI coding tools are significantly increasing software dependency sprawl, with 38% of new dependencies containing known security flaws. This trend raises malware risks as developers often accept unverโ€ฆ

AI coding tools are accelerating dependency sprawl and expanding malware risk with it
VentureBeat โ€” 24 September 2026
Text:
16 0 0

AI coding assistants are speeding up the growth of software dependencies and widening the attack surface for malware, a new analysis by security firm Chainguard found. The report, released Tuesday, says developers using tools such as GitHub Copilot, Tabnine and other largeโ€‘languageโ€‘model based generators are adding twice as many thirdโ€‘party libraries to projects as they did a year ago. The surge in automatically suggested code is creating a sprawling โ€œdependency sprawlโ€ that security teams struggle to track.

The trend reflects a broader shift in software development. Since 2022, AI pair programmers have become mainstream, promising faster code writing and fewer bugs. At the same time, openโ€‘source libraries have multiplied, and many contain known vulnerabilities. Supplyโ€‘chain attacks like the 2021 SolarWinds breach have made firms more wary of hidden risks, but the convenience of AI suggestions often outweighs caution. Developers accept generated snippets without fully vetting the underlying packages, leading to a cascade of unverified components in production code.

Chainguardโ€™s data shows that 38โ€ฏpercent of new dependencies introduced by AIโ€‘generated code have at least one known security flaw, and 12โ€ฏpercent are linked to previously identified malware. In one case, a popular AI tool suggested a snippet that pulled in a library with a backdoor, allowing remote code execution on vulnerable servers. Security researchers say the problem is compounded by the โ€œblackโ€‘boxโ€ nature of the models, which can surface code from compromised repositories without warning. Industry groups are calling for stronger software bill of materials (SBOM) practices and for AI providers to audit the code they suggest.

The report urges developers to treat AIโ€‘generated code as untrusted input, subject to the same review as any thirdโ€‘party library. Chainguard recommends integrating automated dependency scanning into CI pipelines and using provenance data to verify the origin of suggested packages. Some AI tool vendors have pledged to add vulnerability checks before offering code, but experts warn that regulatory guidance may be needed to enforce consistent standards. As AI coding assistants become more entrenched, the balance between productivity and security will shape the next wave of software supplyโ€‘chain defenses.

Read Full Story at VentureBeat โ†’
Advertisement
React:
Sources
Sponsored

More to Read

Waymo is expanding to Singapore
๐Ÿ’ป Technology
Waymo is expanding to Singapore
Engadget ยท 11 days ago
Which major chatbot apps work with CarPlay?
๐Ÿ’ป Technology
Which major chatbot apps work with CarPlay?
Engadget ยท 8 days ago
Is the Samsung Galaxy S24 still worth buying?
๐Ÿ’ป Technology
Is the Samsung Galaxy S24 still worth buying?
Engadget ยท 14 days ago
Giant caves beneath sinkhole reveal origin of mystery trencโ€ฆ
๐Ÿ”ฌ Science
Giant caves beneath sinkhole reveal origin of mystery trenches that score Australia's Nulโ€ฆ
Live Science ยท 6 days ago
Mortgage and refinance interest rates today, Wednesday, Sepโ€ฆ
๐Ÿ“ˆ Markets & Finance
Mortgage and refinance interest rates today, Wednesday, September 16, 2026: Rates ease soโ€ฆ
Yahoo Finance ยท 13 days ago
Aztec manuscript returns to Mexico after two centuries, on โ€ฆ
๐ŸŒ World News
Aztec manuscript returns to Mexico after two centuries, on loan
DW World ยท 11 days ago
Full view