Apr 22 2021

Backdoor Found in Codecov Bash Uploader

Category: BackdoorDISC @ 11:30 am

Developers have discovered a backdoor in the Codecov bash uploader. It’s been there for four months. We don’t know who put it there.

Codecov said the breach allowed the attackers to export information stored in its users’ continuous integration (CI) environments. This information was then sent to a third-party server outside of Codecov’s infrastructure,” the company warned.

Codecov’s Bash Uploader is also used in several uploaders — Codecov-actions uploader for Github, the Codecov CircleCl Orb, and the Codecov Bitrise Step — and the company says these uploaders were also impacted by the breach.

The Surveillance State: Big Data, Freedom, and You

Leave a Reply

You must be logged in to post a comment. Login now.