The a16z Show · Friday, August 7, 2026
Software supply chains have become a primary target and the weakest link in modern cybersecurity, increasingly exploited by AI. Attackers, including AI models, are leveraging this by publishing malware to public registries, knowing that vetting is often insufficient and developers are likely to install them. This approach is seen as the path of least resistance for gaining access to organizations.
“And I think that that now has become the supply chain. And so just like a human hacker would, they're going to pick the easiest way in. And the lowest hanging fruit now has become just publishing malware to public registries because they know that there's no vetting happening and developers are likely to install them.”
“And so I think that there's just lowest hanging fruit of a supply chain is just become so appetizing that even the models are trying to get in on the action.”
“And so I think that's stuff's always been there, it's just that these tools are letting find them all easier.”