Codecov is an organization tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.
Codecov is a organization tracked across 2 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed December 29, 2025; most recent activity March 19, 2026.
Between June and December 2025, the Chinese state group Lotus Blossom compromised the shared hosting provider for Notepad++, redirecting update traffic to deliver malicious installers to targeted users. The attackers…
Software supply chain security has gained prominence, now ranking third on the OWASP Top 10 list for 2025. This shift reflects a rise in attacks targeting the foundational components of software, which exploit trust in…
Codecov is an organization tracked by ThreatCluster, appearing in 2 threat clusters built from 3 intelligence report mentions.
The most recent intelligence report mentioning Codecov on ThreatCluster is dated March 19, 2026. Activity was first observed December 29, 2025, giving a tracked span from then to March 19, 2026.
Across ThreatCluster reporting, Codecov most frequently co-occurs with Crink, Lotus Blossom, Phishing, Ransomware, Supply Chain Attack, among 12 tracked related entities.
The most significant recent cluster is “Chinese State Actor Compromises Notepad++ Update Infrastructure” (2 articles · Updated March 19, 2026). Codecov appears across 2 threat clusters in total, listed above with sources.
Codecov appears in 3 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.