29-07-2026 12:00:00 AM
Metro India News | Hyderabad
The rapid adoption of artificial intelligence in software development is creating new cybersecurity challenges for Indian enterprises, with attackers increasingly targeting developers and software supply chains, according to a new study by Sonatype and Forrester. The findings were highlighted at the Guru Forum held in Hyderabad on Tuesday, where technology and cybersecurity leaders discussed the growing risks linked to AI-driven software development.
The research analysed 9,747 verified malicious software package advisories between January 2020 and May 2026 and found that cyber threats are becoming more targeted. Instead of relying only on large-scale attacks, hackers are now creating fake software packages that closely resemble trusted tools to deceive developers. The study revealed that targeted malicious package advisories increased 75 times in two years, rising from 28 cases in 2023 to 1,576 in 2025. It also found that 47% of malicious packages attempted to imitate trusted software by using familiar names, integrations and utilities.
Experts said the issue is particularly important for India, which has emerged as a major hub for software development, financial technology and Global Capability Centres (GCCs). As companies increasingly use open-source software and AI-assisted coding tools. Abhishek Chauhan, Senior Director of Technology and India Country Head at Sonatype, said enterprises must focus on trusted governance while adopting AI instead of slowing down innovation. Forrester Vice President and Principal Analyst Ashutosh Sharma said organisations need to balance AI-led growth with strong security measures to build resilient digital systems.