logo

Cordyceps Supply chain Vulnerability Impacting Code Repositories at thousands of Organizations

ID: 1f958a7a-c3e7-54cb-962d-cb3b5ac20558

STIX ID: report--1f958a7a-c3e7-54cb-962d-cb3b5ac20558

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Mayura Kathir

...
...

Cordyceps is a class of CI/CD supply-chain vulnerabilities in Git-based workflows (not a single bug) where benign-looking workflow steps can pass untrusted data across trust boundaries, enabling command injection, cross-workflow privilege escalation, credential exfiltration, and artifact poisoning. Novee's large-scale scan found hundreds of instances and validated exploit chains against high-profile projects (Microsoft, Google, Apache, Cloudflare, Python Software Foundation), demonstrating wide-scale impact and the need to treat workflows as first-class code with least-privilege controls and end-to-end attack validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.