# 'Cordyceps' Campaign Exploits CI/CD Pipeline Weaknesses Across Major Open-Source Projects


A coordinated attack campaign known as "Cordyceps" has exposed significant vulnerabilities in the continuous integration and continuous deployment (CI/CD) workflows of five high-profile open-source projects, including critical infrastructure used by millions of developers worldwide. The campaign demonstrates how malicious pull requests can leverage trusted automation systems to execute arbitrary code, potentially compromising downstream applications and user data.


The affected projects—Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache Doris, Cloudflare's Workers SDK, and the Python Software Foundation's Black—represent a cross-section of the modern software development ecosystem. Together, they serve millions of developers and power critical security, infrastructure, and development tooling.


## The Threat: Cordyceps Malicious Pull Requests


The "Cordyceps" campaign represents a sophisticated attack methodology that targets a fundamental assumption in open-source development: that automated CI/CD systems are trusted execution environments. Rather than attempting traditional code injection or exploiting application vulnerabilities, Cordyceps leverages the CI/CD pipeline itself as the attack vector.


Key characteristics of the Cordyceps attack:


  • Poisoned pull requests: Attackers submit seemingly legitimate pull requests that contain malicious code designed to execute during the CI/CD pipeline
  • Trigger mechanisms: The malicious code activates only when specific pipeline conditions are met (e.g., merge to main branch, release builds)
  • Evasion tactics: Code obfuscation and conditional logic help bypass both human reviewers and automated security scanning
  • Multi-stage payloads: Initial payloads may download and execute additional malicious code from remote servers

  • The attack bypasses traditional code review because the malicious activity often remains dormant until the code reaches production or a designated trigger event occurs.


    ## Background and Context: The CI/CD Supply Chain Risk


    CI/CD pipeline exploitation represents one of the cybersecurity industry's most under-discussed attack surfaces. These automated systems execute code with elevated privileges—often including access to:


  • Secrets and credentials for deployment, package registries, and cloud providers
  • Build artifacts that are distributed to millions of users
  • Repository write access to merge code and create releases
  • Release signing keys that validate software authenticity

  • Unlike traditional application vulnerabilities, which require users to download and execute compromised software, a compromised CI/CD pipeline can inject malicious code directly into official releases that users trust completely.


    Historical context:


  • 2021 (SolarWinds): Supply chain attack that infected 18,000+ organizations through compromised build systems
  • 2022 (3CX): Desktop software backdoored through compromised development infrastructure
  • 2023 (XZ Utils): Attempted injection of backdoor code into widely-used compression library via malicious contributions

  • The Cordyceps campaign represents an evolution: systematically targeting multiple critical projects rather than isolating single victims.


    ## Affected Projects and Attack Surface


    ### Microsoft Azure Sentinel

    Azure Sentinel is Microsoft's cloud-native security information and event management (SIEM) platform, used by thousands of enterprises for threat detection and incident response. A compromise at this level could allow attackers to:

  • Inject false alerts to obscure real attacks
  • Exfiltrate security telemetry from monitored organizations
  • Maintain persistence across customer environments

  • ### Google AI Agent Development Kit

    As AI agent frameworks become central to enterprise automation, compromising development tools could lead to trojanized AI agents deployed across organizations—potentially undetectable because they mimic legitimate system behavior.


    ### Apache Doris Analytics Database

    Doris is an open-source analytics database used for real-time OLAP workloads across financial services, e-commerce, and data-intensive industries. Database system compromise represents one of the highest-impact attack scenarios.


    ### Cloudflare Workers SDK

    Cloudflare Workers enable serverless code execution across Cloudflare's edge network. A compromised SDK could inject malicious logic into functions that process millions of HTTP requests daily.


    ### Python Software Foundation's Black

    Black is a code formatter used by the Python community and integrated into development workflows across countless projects. Compromising Black creates a cascading risk: every developer who automatically formats their code could inadvertently introduce malicious transformations.


    ## Technical Details: How Cordyceps Executes


    The Cordyceps attack exploits several technical weaknesses:


    | Vulnerability | How It's Exploited |

    |---|---|

    | Over-permissioned CI/CD tokens | GitHub Actions and similar CI systems often have access tokens with broader permissions than necessary |

    | Conditional execution logic | Malicious code executes only on specific branches or tags, bypassing superficial review |

    | Obfuscated payload delivery | Code fetches actual malicious payload from attacker infrastructure during pipeline execution |

    | Trusting internal dependencies | CI/CD systems trust inter-dependencies and build scripts without validation |

    | Release automation workflows | Automated release pipelines execute code without manual approval gates |


    A typical attack flow:


    1. Reconnaissance: Attacker studies target project's CI/CD configuration (often public in .github/workflows/ directories)

    2. Submission: Malicious PR is submitted with innocent-appearing code changes alongside hidden trigger logic

    3. Review bypass: Code changes appear legitimate; malicious logic is time-bombed or conditionally activated

    4. Execution: When PR is merged and pipeline runs, malicious code executes with full pipeline privileges

    5. Persistence: Attacker-controlled code modifies release artifacts or injects code into published packages

    6. Distribution: Compromised software reaches end users through official channels


    ## Implications: Who's at Risk


    The impact of successful Cordyceps attacks extends far beyond the directly affected projects:


    For developers and organizations:

  • Downstream consumers of these projects receive compromised dependencies
  • Automated dependency updates could unknowingly pull malicious code
  • Supply chain risk becomes transitive: your vendors' vendors can compromise you

  • For specific sectors:

  • Financial services: Compromised Doris deployments could enable fraud or data theft
  • Security operations: Azure Sentinel compromise could blind defenders during active attacks
  • Cloud infrastructure: Workers SDK compromise could target millions of websites
  • Software development: Black compromise affects almost every Python developer

  • Attack persistence:

    Once malicious code is published in an official release, it typically remains in historical versions. Organizations using older releases remain vulnerable indefinitely unless they actively patch.


    ## Recommendations: Defensive Measures


    ### For Open-Source Projects


  • Implement principle of least privilege: CI/CD tokens should have minimal necessary permissions; use separate tokens for different tasks
  • Require approval gates: High-risk operations (releases, secret access) should require manual approval
  • Monitor pull requests for red flags: Unusual access patterns, new contributors modifying build scripts, code that only executes conditionally
  • Use code signing: Sign all releases cryptographically so users can verify authenticity
  • Regular access audits: Review who has write access to main branch, release permissions, and secret access

  • ### For Organizations Using These Projects


  • Implement software bill of materials (SBOM): Know exactly which dependencies and versions you're using
  • Use dependency verification: Enable hash verification for downloaded dependencies rather than relying solely on package repositories
  • Monitor for suspicious updates: Alert on unusual update patterns or version jumps from trusted dependencies
  • Isolate CI/CD systems: Run builds in sandboxed environments with limited network access
  • Audit supply chain: Regularly review your dependency tree for high-risk dependencies

  • ### For Platform Providers


  • Enhance audit logging: GitHub Actions, GitLab CI, and similar platforms should provide comprehensive audit trails of token usage
  • Implement default-deny policies: Restrict token scopes by default; require explicit opt-in for broad permissions
  • Detect anomalous behavior: Flag CI/CD jobs that exhibit suspicious patterns (downloading unsigned code, accessing secrets unusually)

  • ## HackWire Analysis


    The Cordyceps campaign exposes a critical blind spot in how the software development industry thinks about security. We focus extensively on application vulnerabilities, penetration testing, and endpoint protection—but we've largely treated CI/CD systems as trusted infrastructure that doesn't require the same scrutiny.


    This represents a fundamental misunderstanding of modern attack surface. Your CI/CD system is not auxiliary infrastructure; it is the foundational trust layer upon which all your software is built. A compromised CI/CD pipeline is orders of magnitude more dangerous than a compromised production server because it corrupts the source of truth itself.


    What makes Cordyceps particularly concerning is the targeting pattern. These aren't random projects; they're infrastructure tools used by millions of developers. Attacking Black, for instance, is equivalent to poisoning a widely-used pharmaceutical supply—the attacker gets one injection point but affects orders of magnitude more victims. This suggests a sophisticated threat actor (likely state-sponsored or advanced criminal group) practicing long-term strategic thinking rather than opportunistic exploitation.


    The broader pattern is clear: supply chain attacks have moved from exploitation of poor DevOps practices to systematic abuse of the open-source development model itself. The model's strength—collaborative review by many eyes—becomes its weakness when attack automation is sophisticated enough to evade code review and execute only after code has been trusted and merged.


    Organizations should treat this not as isolated incidents but as confirmation that supply chain compromise is now a primary attack vector. If you're not actively monitoring your dependency pipeline, implementing cryptographic verification, and designing for supply chain resilience, you're operating with last-decade's threat model.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Tools](https://www.hackwire.news/category/tools) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)