Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A threat campaign called ‘Cordyceps’ is targeting CI/CD pipelines across five high-profile open source projects, including Microsoft Azure Sentinel, Google AI ADK, Apache Doris, the Cloudflare Workers SDK, and the Python Black formatter, by submitting malicious pull requests that execute code inside automated build and test workflows. If successful, attackers can poison software artifacts distributed to thousands of downstream organizations that depend on these projects. The business risk is supply chain contamination: software your teams build or deploy using these projects could unknowingly carry adversary-inserted code. Attribution and campaign scope are based on third-party reporting and have not been independently confirmed by affected vendors or CISA.

Author

Tech Jacks Solutions