2021 Codecov supply chain — potential GPG signing key exposure at HashiCorp
Data compromised
Signing keys and CI secrets at risk per vendor disclosure; no customer PII inventory in public summary
Technical writeup
HashiCorp reported impact from the Codecov-supply-chain compromise of a bash uploader script used in CI: environment credentials accessible to the trojanized script could include a GPG private key HashiCorp used to sign releases and a related passphrase. The vendor rotated signing material, revoked the prior key, and published HCSEC-2021-12 guidance. This case concerns release-integrity tooling rather than a dump of end-user product databases.
Root cause
Third-party CI telemetry script compromise (Codecov) leading to secret exfiltration risk in pipelines