'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
Malicious pull requests dubbed 'Cordyceps' exploit CI/CD workflow weaknesses in major projects including Azure Sentinel, Google AI Dev Kit, and Cloudflare Workers — a supply-chain threat at the build-pipeline level.
Summary written by editorial AI · Source link below
The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK, and Python Software Foundation's Black.
Editorial Analysis
If CI/CD pipelines in tier-one open-source projects are vulnerable to malicious PRs, any enterprise consuming those dependencies inherits build-time supply-chain risk.
Audit CI/CD workflow permissions on your public and internal repositories, ensuring pull requests from external contributors cannot trigger privileged pipeline actions.
A new class of supply-chain attack targets the build pipelines of major open-source projects that enterprises depend on daily.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.
More from the DevSecOps Desk
- CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages20 Jul
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts19 Jul
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT17 Jul
- VulnHunter: Capital One's agentic AI code security tool17 Jul
- The Prover Is the Judge: Verified Security Software from AI Coding Agents in Ada/SPARK17 Jul