Codecov — Cyber Attacks, Breaches & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
December 29, 2025
Last Seen
August 15, 2026

Related Threat Clusters

  • Chinese State Actor Compromises Notepad++ Update Infrastructure

    Between June and December 2025, the Chinese state group Lotus Blossom compromised the shared hosting provider for Notepad++, redirecting update traffic to deliver malicious installers to targeted users. The attackers…

    2 articles · Updated March 19, 2026
  • Codecov Bash Uploader Security Incident Overview

    On April 1, 2021, Codecov discovered unauthorized modifications to its Bash Uploader script, which allowed a threat actor to extract sensitive information from users' CI environments. The malicious changes targeted…

    2 articles · Updated August 15, 2026
  • Software Supply Chain Threats Surge to OWASP Top 10

    Software supply chain security has gained prominence, now ranking third on the OWASP Top 10 list for 2025. This shift reflects a rise in attacks targeting the foundational components of software, which exploit trust in…

    2 articles · Updated January 9, 2026

Recent Intelligence Reports

  • Codecov's postmortem — about.codecov.io · August 15, 2026
  • Security Update — about.codecov.io · August 15, 2026
  • Defending Supply Chain Software Pipelines Against Nation — Mbtmag · March 19, 2026
  • Defending Supply Chain Software Pipelines Against Nation — Mbtmag · March 19, 2026
  • Rising Software Supply Chain Attacks: AI Risks and Essential Defenses — Webpronews · December 29, 2025

CVSS v3.1 Breakdown