← Contrast Security

2021 Contrast Security — Codecov CI supply chain exposure customer advisory

2021 Unknown records affected Share on X

Data compromised

CI secrets and repository access where pipelines integrated Codecov per vendor advisory.

Technical writeup

Contrast Security issued a statement after the Codecov bash uploader compromise, describing potential access to CI secrets tied to repositories that used the tainted uploader.

Root cause

Tampered third-party CI uploader enabling secret exfiltration across many vendors.

References