2021 Contrast Security — Codecov CI supply chain exposure customer advisory
Data compromised
CI secrets and repository access where pipelines integrated Codecov per vendor advisory.
Technical writeup
Contrast Security issued a statement after the Codecov bash uploader compromise, describing potential access to CI secrets tied to repositories that used the tainted uploader.
Root cause
Tampered third-party CI uploader enabling secret exfiltration across many vendors.