Codecov Bash Uploader Security Incident Overview

Codecov Bash Uploader Security Incident Overview

First seen 15 Aug 2026, 02:19 UTC about.codecov.io 78% similarity 70.5

Article Content

Browse articles
ThreatCluster

On April 1, 2021, Codecov discovered unauthorized modifications to its Bash Uploader script, which allowed a threat actor to extract sensitive information from users' CI environments. The malicious changes targeted users of the Bash Uploader, Codecov GitHub Action, CircleCI Orb, and Bitrise Step. The attacker exploited a flaw in Codecov's Docker image creation process to gain access to credentials. Affected users were notified via email and in-app alerts. Codecov engaged a third-party forensic firm to investigate the breach and implemented security measures to prevent future incidents. The incident was reported to law enforcement, and Codecov took steps to revoke compromised keys and audit their systems. The investigation revealed that the unauthorized access began on January 31, 2021, and continued until the incident was detected.

Key Points: • Unauthorized access to Codecov's Bash Uploader script occurred from January 31, 2021. • Sensitive information, including environment variables, may have been exposed to the attacker. • Affected users received notifications and guidance on assessing their exposure.

ThreatCluster AI How this analysis works

Timeline

2021-01-31
Unauthorized access began
The threat actor started modifying the Bash Uploader script, potentially exposing user data.
Article 1
2021-04-01
Incident detected
A customer reported a SHA256 discrepancy in the Bash Uploader, prompting an investigation.
Article 2
2021-04-01
Mitigation efforts initiated
Codecov removed the malicious changes and implemented controls to prevent future attacks.
Article 2
2021-04-15
User notifications sent
Affected users were emailed and notified in-app about the potential exposure of sensitive data.
Article 1
2021-04-29
Security update published
Codecov released an update detailing the incident and the indicators of compromise (IOCs).
Article 1

Community

Browse all →

Tracked Entities in This Story