Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
build-pipeline-compromiseprivilege-escalation-methodcredential-access-methodopen-source-dependency-vulnerability

Cordyceps GitHub Actions Flaw Enabled CI/CD Pipeline Hijacking

Updated 5h agoFirst seen Jun 23, 20265 sources

Researchers at Novee disclosed Cordyceps, a class of systemic software supply chain flaws in GitHub Actions workflows that can let attackers hijack build and release pipelines through insecure trust-boundary crossings in CI/CD YAML configurations. The attack chains combine issues such as command injection, broken authentication logic, artifact poisoning, and privilege escalation across multiple workflows rather than a single misconfiguration. Novee said exploitation may require only a pull request or even a pull request comment from a free GitHub account, allowing low-privilege or unauthenticated attackers to execute malicious code, steal credentials, and potentially gain control of code repositories and connected cloud environments.

After scanning roughly 30,000 high-impact repositories, Novee flagged 654 projects and verified more than 300 as fully exploitable. Confirmed impact included repositories tied to Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation, with examples including Azure Sentinel, Google adk-samples, Apache Doris, Black, and Cloudflare Workers tooling. The researchers said affected organizations have fixed the disclosed issues, but warned that AI coding agents are helping spread the same insecure CI/CD patterns across ecosystems including npm, PyPI, crates, and Go.

Share:
Cordyceps GitHub Actions Flaw Enabled CI/CD Pipeline Hijacking
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 23, 20261d ago

Novee publicly discloses the Cordyceps vulnerability class

Novee disclosed Cordyceps as a systemic GitHub Actions CI/CD supply-chain vulnerability class caused by insecure interactions across workflows, enabling attacks such as command injection, artifact poisoning, broken authentication abuse, and privilege escalation.

Cordyceps Supply Chain Flaw Impacting Code Repositories at thousands of Organizations

Major organizations fix Cordyceps-related workflow vulnerabilities

Confirmed fixes were made for affected repositories tied to organizations including Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation after Novee disclosed the issues to tested projects.

Cordyceps Supply Chain Flaw Impacting Code Repositories at thousands of Organizations

Novee scans 30,000 repositories and verifies 300+ exploitable chains

Novee researchers scanned about 30,000 high-impact GitHub repositories, flagged hundreds of projects, and verified more than 300 as fully exploitable through the Cordyceps CI/CD vulnerability class.

Cordyceps Supply Chain Flaw Impacting Code Repositories at thousands of Organizations
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
1 linked
Affected products
4 linked
BlackAzure SentinelDorisAzure Marketplace
Organizations
11 linked
CloudflareMicrosoft CorporationGoogleNoveePython Software FoundationAmazon Web ServicesApache Software FoundationDark ReadingGitHubHackread.comNetlify
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.