CI/CD Compromise 2021 Incident #47

Codecov bash uploader

Estimated Financial Impact
$50-100M+
Blast Radius
29K enterprise customers; HashiCorp, Twilio, Rapid7, Mercari

What Happened

Attackers exploited a Docker image creation error in Codecov's build process to modify their Bash Uploader script, adding code that exfiltrated all CI/CD environment variables to an attacker-controlled server. Undetected for ~2 months. HashiCorp's GPG signing key was exposed, Mercari lost 17,085 customer financial records, and at least 5 other companies publicly disclosed being affected.

Sources: Codecov postmortem · HashiCorp disclosure · Rapid7 response

✓

Risk Guard: Caught

ARTIFACT_HASH_MISMATCH automates the exact SHA verification that discovered this breach

Risk Guard Check Codes That Flag This Incident

ARTIFACT_HASH_MISMATCHPACKAGE_ACTIVE_MALWARE

How Every Tool Performed

1 Caught 0 Partial 5 Missed
Tool Verdict Details
OSS Risk Guard Caught ARTIFACT_HASH_MISMATCH automates the exact SHA verification that discovered this breach
Socket Missed Package-level tool; Codecov was a bash script, not a package
Snyk Missed No CI/CD integrity checking
Sonatype (Nexus) Missed No CI/CD script integrity checking
Black Duck Missed No CI/CD integrity checking
Endor Labs Missed No CI/CD integrity checking
← @0xengine/xmlrpc SolarWinds / Sunburst →