Sonatype and Forrester Address AI-Era Software Supply Chain Risks for Indian Enterprises in the Guru Forum
onatype, a leader in enabling enterprises to accelerate agentic software development, has partnered with Forrester to bring together technology, cybersecurity, and business leaders in India. The forum examines how artificial intelligence is reshaping software supply chain risks and what measures organizations must take to respond.
The discussion draws insights from Sonatype’s latest research, titled “The Trust Economy of Software: How AI is Reshaping Software Supply Chain Risk for Financial Services.” Based on an analysis of 9,747 verified malicious package advisories collected between January 2020 and May 2026, alongside enterprise telemetry from the financial services sector, the study reveals a fundamental evolution in attacker behavior.
Key Research Findings on Precision Attacks:
The study highlights several critical shifts in software supply chain security:
Targeted Advisories Surge: Targeted malicious package advisories increased 75-fold over a two-year period, climbing from 28 in 2023 to 1,576 in 2025.
Impersonation Tactics: Approximately 47% of malicious packages now impersonate trusted software by leveraging familiar names, integrations, and utilities to appear legitimate.
Developer Targeting: In 2025, 53% of analyzed malicious packages targeted developers directly during the installation phase, occurring before traditional security controls could intervene.
Advanced Techniques: More than one in four malicious package advisories currently utilize advanced techniques such as obfuscation, multi-stage droppers, and backdoors.
Implications for Indian Enterprises and GCCs:
These findings carry substantial weight for India, which serves as one of the world’s fastest-growing software development hubs and a global epicenter for financial technology, digital engineering, and Global Capability Centres (GCCs). As Indian enterprises and GCCs expand their reliance on open-source software, third-party components, and AI-assisted development, governing what enters the software lifecycle has emerged as a strategic business priority, emphasizing that security must begin before a component enters the build rather than after production.
Leadership Perspectives
Commenting on the shift in threat dynamics, Abhishek Chauhan, Senior Director of Technology and India Country Head at Sonatype, stated:
“AI is helping development teams assemble software faster, but it is also accelerating the number of decisions they make about what software to trust. Attackers understand that shift. They are no longer relying only on scale; they are investing in precision attacks that look familiar, targeting developers directly, and executing before traditional controls have a chance to intervene. For Indian enterprises and GCCs, the priority is not to slow AI adoption. It is to establish trusted governance at the point where software enters development.”
Speaking at the event, Ashutosh Sharma, VP and Principal Analyst at Forrester, noted that software development is entering a transformative phase as AI alters not only code creation but also how software components are discovered, selected, and integrated. As organizations accelerate AI adoption, governance must evolve alongside development practices to balance innovation with resilience.






