Researchers at Novee disclosed Cordyceps, a class of systemic software supply chain flaws in GitHub Actions workflows that can let attackers hijack build and release pipelines through insecure trust-boundary crossings in CI/CD YAML configurations. The attack chains combine issues such as command injection, broken authentication logic, artifact poisoning, and privilege escalation across multiple workflows rather than a single misconfiguration. Novee said exploitation may require only a pull request or even a pull request comment from a free GitHub account, allowing low-privilege or unauthenticated attackers to execute malicious code, steal credentials, and potentially gain control of code repositories and connected cloud environments.
After scanning roughly 30,000 high-impact repositories, Novee flagged 654 projects and verified more than 300 as fully exploitable. Confirmed impact included repositories tied to Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation, with examples including Azure Sentinel, Google adk-samples, Apache Doris, Black, and Cloudflare Workers tooling. The researchers said affected organizations have fixed the disclosed issues, but warned that AI coding agents are helping spread the same insecure CI/CD patterns across ecosystems including npm, PyPI, crates, and Go.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Novee disclosed Cordyceps as a systemic GitHub Actions CI/CD supply-chain vulnerability class caused by insecure interactions across workflows, enabling attacks such as command injection, artifact poisoning, broken authentication abuse, and privilege escalation.
Confirmed fixes were made for affected repositories tied to organizations including Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation after Novee disclosed the issues to tested projects.
Novee researchers scanned about 30,000 high-impact GitHub repositories, flagged hundreds of projects, and verified more than 300 as fully exploitable through the Cordyceps CI/CD vulnerability class.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
thenewstack.io
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcehackread.com
Open sourcecybersecuritynews.com
Open sourcedarkreading.com
Open sourcedocs.github.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.