← HashiCorp

2021 Codecov supply chain — potential GPG signing key exposure at HashiCorp

2021 Unknown records affected Share on X

Data compromised

Signing keys and CI secrets at risk per vendor disclosure; no customer PII inventory in public summary

Technical writeup

HashiCorp reported impact from the Codecov-supply-chain compromise of a bash uploader script used in CI: environment credentials accessible to the trojanized script could include a GPG private key HashiCorp used to sign releases and a related passphrase. The vendor rotated signing material, revoked the prior key, and published HCSEC-2021-12 guidance. This case concerns release-integrity tooling rather than a dump of end-user product databases.

Root cause

Third-party CI telemetry script compromise (Codecov) leading to secret exfiltration risk in pipelines

References