Trusted CI Workflows Become the Supply-Chain Weak Point

The break is in the workflow, not the code review. A pull request can push attacker-controlled content into trusted automation, and that automation may already hold signing keys, deploy tokens, or cloud access the attacker can inherit. Novee researcher Elad Meged says the Cordyceps class affects repositories across Microsoft, Google, Apache, Cloudflare, and Python. A single scan flagged 654 potentially exploitable repositories, with 300 confirmed fully exploitable, including Azure Sentinel, AI Agent Development Kit, Apache Doris, Cloudflare Workers SDK, and Python Black. That shifts the trust boundary from the PR itself to the CI job running behind it. If a repo lets pull-request workflows touch secrets or signing privileges, the same exposure can turn review gates into a path for credential theft, forged checks, malicious package publishing, and other supply-chain outcomes.

Part of the PlainSec briefing for 2026-06-25

Sources