As cited
Copy frozen at (site build).
threat intel
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
A campaign dubbed 'Cordyceps' exploits CI/CD pipeline weaknesses to inject malicious pull requests into high-profile open source projects including Azure Sentinel, Google's AI Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black formatter. The attacks leverage automated workflows to introduce compromised code into widely-used developer tools and libraries. This represents a supply chain threat targeting projects with significant downstream dependents.
Why it matters: Open source maintainers and developers using these affected projects risk pulling malicious code into their build pipelines. Organizations should review pull request approval processes and monitor their CI/CD workflows for suspicious activity, especially those with high dependency counts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
A campaign dubbed 'Cordyceps' leverages malicious pull requests to exploit CI/CD pipeline vulnerabilities in widely used software projects. The affected targets include Microsoft Azure Sentinel, Google's artificial intelligence (AI) Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black formatter.
Why it matters: Developers and platform teams using these projects face supply chain risk if malicious code merges into builds; patch or monitor pull requests immediately in affected repositories.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
A campaign dubbed 'Cordyceps' leverages malicious pull requests to exploit CI/CD pipeline vulnerabilities in widely used software projects. The affected targets include Microsoft Azure Sentinel, Google's artificial intelligence (AI) Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python's Black formatter.
Why it matters: Developers and platform teams using these projects face supply chain risk if malicious code merges into builds; patch or monitor pull requests immediately in affected repositories.
- Source published
- First seen by Cybersecurity Tracker