← All writing

[ Cybersecurity · · 8 min read ]

Software Supply Chain Attacks in 2026: The Expanding Threat Landscape

Supply chain attacks have evolved from targeting build systems to compromising AI model registries, open-source training data and inference APIs.

The software supply chain attack surface has expanded dramatically as organisations integrate AI components into their technology stacks. While the security community has invested heavily in securing traditional supply chain vectors — package registries, CI/CD pipelines and build systems — a new class of AI-specific supply chain risks has emerged that most organisations are not yet equipped to manage. The convergence of open-source AI models, third-party training data and shared inference infrastructure creates novel trust boundaries that adversaries are actively probing.

Model supply chain attacks represent the most significant new vector. Organisations routinely download pre-trained models from public registries like Hugging Face, use transfer learning on top of third-party foundation models and deploy models that were trained on data they did not curate. Each of these dependencies introduces a trust assumption that can be exploited. Researchers have demonstrated that backdoored models can be published to public registries with malicious behaviours that activate only under specific trigger conditions — passing standard evaluation benchmarks while containing hidden vulnerabilities.

The training data supply chain presents equally concerning risks. Models trained on web-scraped data inherit whatever biases, errors and malicious content exist in their sources. Adversaries can poison open-source datasets used for fine-tuning, inject malicious content into web pages likely to be scraped by training pipelines and manipulate the benchmarks used to evaluate model quality. The result is a supply chain where integrity is difficult to verify and provenance is often impossible to establish.

Defending against AI supply chain attacks requires a combination of traditional software supply chain security practices and novel AI-specific controls: model provenance tracking and signature verification, integrity validation for training datasets, behavioural testing that goes beyond standard benchmarks to probe for backdoor triggers, and inference-time monitoring that detects anomalous model behaviour indicative of supply chain compromise.

Written by Ganesh Khetawat, founder of Aletheia AI

Need this built? See our cybersecurity and auditing work, or tell us what you’re building.

[ Your turn ]

Have a hard problem?
Let’s build the answer.