Attackers exploited a Docker image creation error in Codecov's build process to modify their Bash Uploader script, adding code that exfiltrated all CI/CD environment variables to an attacker-controlled server. Undetected for ~2 months. HashiCorp's GPG signing key was exposed, Mercari lost 17,085 customer financial records, and at least 5 other companies publicly disclosed being affected.
Sources: Codecov postmortem · HashiCorp disclosure · Rapid7 response
ARTIFACT_HASH_MISMATCH automates the exact SHA verification that discovered this breach
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | ARTIFACT_HASH_MISMATCH automates the exact SHA verification that discovered this breach |
| Socket | Missed | Package-level tool; Codecov was a bash script, not a package |
| Snyk | Missed | No CI/CD integrity checking |
| Sonatype (Nexus) | Missed | No CI/CD script integrity checking |
| Black Duck | Missed | No CI/CD integrity checking |
| Endor Labs | Missed | No CI/CD integrity checking |