DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

Malicious Pull Requests Compromise AI and Developer Toolchains via CI/CD Flaws

Forensic Summary

A campaign dubbed 'Cordyceps' is exploiting weaknesses in CI/CD workflows to inject malicious pull requests into high-profile open-source projects, including Google's AI Agent Development Kit and Microsoft's Azure Sentinel. The attack surface spans multiple trusted ecosystems, meaning poisoned code could propagate into AI tooling, cloud infrastructure, and widely-used developer utilities before detection. The breadth of targets — including Python's Black formatter — signals a supply chain strategy designed to maximise downstream blast radius.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/malicious-pull-requests-compromise-ai-and-developer-toolchains-via-ci-cd-flaws/

Top comments (0)