Back to all lessons
Awareness Lessons
4 months ago

Malicious Pull Requests Poison CI/CD Pipelines Across Major Open-Source Projects

The 'Cordyceps' threat exploits weaknesses in CI/CD pipeline configurations to inject malicious code through seemingly legitimate pull requests, compromising major open-source projects before maintainers can review them. The root cause lies in overly permissive automation workflows that execute untrusted code from external contributors without adequate sandboxing or approval gates. This matters because a single compromised open-source dependency can cascade downstream to thousands of organizations relying on those projects. The attack demonstrates how supply chain threats have evolved beyond tampering with packages to directly subverting the development and build process itself.

Tactical Insight

Immediate actions

  • Audit all CI/CD pipeline configurations to ensure workflows triggered by external pull requests cannot access secrets or privileged environments.
  • Restrict the `pull_request_target` GitHub Actions trigger (and equivalents) so it never runs untrusted contributor code with elevated permissions.
  • Require mandatory human review and approval before any CI/CD job executes code from first-time or external contributors.

Long-term improvements

  • Implement branch protection rules and required code-owner sign-off before automated pipelines are permitted to run against incoming changes.
  • Adopt a least-privilege model for CI/CD service accounts, scoping secrets and tokens only to the specific jobs that require them.
  • Integrate Software Composition Analysis (SCA) and pipeline security scanning tools (e.g., StepSecurity, Semgrep) into your DevSecOps workflow.

Detection measures

  • Enable detailed audit logging for all CI/CD pipeline executions, capturing who triggered a run, what code was used, and what secrets were accessed.
  • Set up alerting for anomalous pipeline behaviors such as unexpected outbound network connections, secret access from fork-based builds, or new workflow file changes.
  • Regularly review and monitor open-source project dependency trees for newly introduced or modified CI/CD workflow files.