CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 117

As cited

Copy frozen at (site build).

threat intel

'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows

A campaign dubbed 'Cordyceps' exploits CI/CD pipeline weaknesses to inject malicious pull requests into high-profile open source projects including Azure Sentinel, Google's AI Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black formatter. The attacks leverage automated workflows to introduce compromised code into widely-used developer tools and libraries. This represents a supply chain threat targeting projects with significant downstream dependents.

Why it matters: Open source maintainers and developers using these affected projects risk pulling malicious code into their build pipelines. Organizations should review pull request approval processes and monitor their CI/CD workflows for suspicious activity, especially those with high dependency counts.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows

A campaign dubbed 'Cordyceps' leverages malicious pull requests to exploit CI/CD pipeline vulnerabilities in widely used software projects. The affected targets include Microsoft Azure Sentinel, Google's artificial intelligence (AI) Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black formatter.

Why it matters: Developers and platform teams using these projects face supply chain risk if malicious code merges into builds; patch or monitor pull requests immediately in affected repositories.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows

A campaign dubbed 'Cordyceps' leverages malicious pull requests to exploit CI/CD pipeline vulnerabilities in widely used software projects. The affected targets include Microsoft Azure Sentinel, Google's artificial intelligence (AI) Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black formatter.

Why it matters: Developers and platform teams using these projects face supply chain risk if malicious code merges into builds; patch or monitor pull requests immediately in affected repositories.

VendorsMicrosoftGoogleCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary