AI coding agents are making software supply-chain attacks easier to scale—and harder to notice.
You ask your coding agent to “add relative timestamps to the activity feed.” Forty seconds later, it’s done.
The diff looks clean.
The tests pass.
The feed says “3 minutes ago.”
You skim the component, approve the PR, and merge.
You reviewed the code it wrote.
Hopefully.
But did you review the code it installed?
Probably not.
That innocent-looking line in package.json can introduce an entire dependency tree: someone else’s code, their dependencies, and whatever their installation scripts decide to execute on your machine.
And your machine might have your SSH keys, npm tokens, cloud credentials, and access to production.
In 2026, this isn’t theoretical anymore.