Cordyceps flaws let anyone with a free GitHub account hijack CI/CD pipelines at Microsoft, Google, and Apache

Source Cryptopolitan

Security firm Novee has revealed Cordyceps as a class of exploitable CI/CD vulnerabilities across open-source repositories that allowed attackers to steal credentials, push malicious code, and compromise operations at some of the world’s largest software organizations.

These vulnerabilities have been found across repositories belonging to Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation, which the firms have also claimed to have fixed. 

What is the Cordyceps vulnerability? 

The security firm Novee has uncovered a dangerous new class of vulnerabilities in CI/CD pipelines that it refers to as “Cordyceps.” The name “Cordyceps” comes from a parasitic fungus that takes over its host, as this flaw lets anyone with a free GitHub account take control of popular open-source projects. 

The vulnerabilities were discovered across repositories belonging to Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation. A single scan of 30,000 repositories revealed 300 fully exploitable attack chains. 

Attackers are able to steal credentials, inject malicious code, and compromise software supply chains through these vulnerabilities. The issues have been fixed, but researchers warn that AI coding assistants will keep reproducing them across millions of repositories. 

GitHub Actions workflows handle important tasks like running tests, building software, and publishing releases, but they are often treated as simple configuration files rather than security-critical code. 

The attack chain usually begins when an outsider, which can be anyone with a free GitHub account, submits a pull request or leaves a comment on a public repository. A low-privilege workflow that accepts the outsider’s input as if it were trusted data is then activated.

From there, the output flows into a second workflow that runs with elevated permissions. This second workflow might hold cloud provider authentication tokens, package registry credentials, or signing keys. And at this point, the attacker can either steal non-expiring tokens or permanently compromise the repository. 

According to security researchers, every individual step in these chains can pass a security audit on its own. The vulnerability only appears when someone traces the path of untrusted data across the full sequence of workflow handoffs. 

Which major companies were affected by the vulnerability?

Novee found and reported confirmed vulnerabilities at some of the world’s largest technology organizations. 

Microsoft’s Azure Sentinel, for instance, contained a pull request comment that could trigger attacker code execution on Microsoft’s CI infrastructure and steal a non-expiring GitHub App key. This key would have granted persistent write access to security detection content that Microsoft distributes to customer Sentinel workspaces.

Google’s AI Agent Development Kit repository, with over 9,200 GitHub stars, had a flaw in which a single pull request could let an attacker gain the highest permission level (roles/owner) on the associated Google Cloud project. 

In Apache’s Doris Analytics Database, researchers found two zero-click attack paths. One allowed a comment on any pull request to steal hardcoded CI credentials, while the other let a forked pull request steal a token with full write permissions across code, packages, and pages. 

Cloudflare’s Workers SDK, built around the Wrangler CLI toolchain, was vulnerable to arbitrary command execution triggered by a specially crafted branch name. 

The Python Software Foundation’s Black code formatter, which has over 130 million downloads, had a flaw where any pull request could steal the project’s automation bot token, which could then approve further pull requests.

Novee confirmed to Dark Reading that none of these workflow patterns were exploited before patches were applied. 

Meged recommends that CISOs treat CI/CD workflow files as security-critical code.

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Asian Currencies Steady Near Lows as Yen Hovering Near 160 Triggers Intervention WatchAsian markets stabilized following a sharp selloff, balanced by a fragile Middle East ceasefire and strong U.S. economic data that fueled expectations of prolonged high Federal Reserve interest rates.
Author  Mitrade Team
6 Month 04 Day Thu
Asian markets stabilized following a sharp selloff, balanced by a fragile Middle East ceasefire and strong U.S. economic data that fueled expectations of prolonged high Federal Reserve interest rates.
placeholder
Will the Tech Rally Continue? The Technical Verdict on the NASDAQ 100 Riding a massive 32% post-earnings wave, the Nasdaq-100 is showing its first signs of exhaustion. We break down crucial exit and entry rules for long positions this week.
Author  Mitrade Team
6 Month 05 Day Fri
Riding a massive 32% post-earnings wave, the Nasdaq-100 is showing its first signs of exhaustion. We break down crucial exit and entry rules for long positions this week.
placeholder
Tech Rout and Rate Hike Fears Drag Asian Stocks LowerAsian equities retreated on Friday as investors locked in technology profits ahead of U.S. payroll data, while South Korean labor friction and Japanese rate-hike speculation compounded regional market losses.
Author  Mitrade Team
6 Month 05 Day Fri
Asian equities retreated on Friday as investors locked in technology profits ahead of U.S. payroll data, while South Korean labor friction and Japanese rate-hike speculation compounded regional market losses.
placeholder
US Attacks Iran Amid the “Ceasefire”: Bitcoin, Gold, and Oil ReactThe United States launched strikes against Iran on Tuesday after a US Apache helicopter was downed over the Strait of Hormuz, breaking the fragile ceasefire previously announced by President Donald Tr
Author  Mitrade Team
6 Month 10 Day Wed
The United States launched strikes against Iran on Tuesday after a US Apache helicopter was downed over the Strait of Hormuz, breaking the fragile ceasefire previously announced by President Donald Tr
placeholder
Gold Price Analysis (XAU/USD): Gold Falls to 6-Month Low as Inflation Fuels Rate Hike Bets, A Buying Opportunity or a Falling Knife? Gold hit a 6-month low on Fed rate hike bets. However, strong central bank buying and technical indicators suggest potential tactical bounces and long-term accumulation windows.
Author  Mitrade Team
6 Month 12 Day Fri
Gold hit a 6-month low on Fed rate hike bets. However, strong central bank buying and technical indicators suggest potential tactical bounces and long-term accumulation windows.
goTop
quote