← Incident database

codecov-2021 · Disclosed 2021-04-15

Codecov: leaked image credential and CI script tampering

A credential in a public Docker image layer enabled tampering with the Bash Uploader. The modified script exported CI environment information from affected users.

CredentialsSupply chain / CI

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    An HMAC key extracted from an intermediate image layer allowed modification of the distributed uploader.

    [s2]Root Cause
  • Reported fact

    The modified uploader transmitted environment variables and Git remote information.

    [s1]About the Event

Timeline

  1. Beginning of observed script modifications. [s1]

  2. Detected after a customer checksum check. [s2]

  3. Disclosure and customer response guidance published. [s1]

Reported response

  • Reported fact

    Credentials were revoked and rotated; public image build practices were changed.

    [s2]Recovery

Evidence relevant to prevention

Operational controls to inspect

Deleting a secret from the final filesystem can leave it in layers. Inspect distributed artifacts and CI execution permissions.

Editorial assessment; not a determination of liability. [s1][s2]

Unknowns and AI involvement

AI involvementUnknown

The cited primary sources do not establish AI involvement. This does not establish that AI was absent.

Customer exposure depends on the CI environment and execution history.

Sources

  1. [s1] Codecov · Primary source

    Bash Uploader Security Update ↗

    Published 2021-04-15 · Reviewed 2026-10-02

  2. [s2] Codecov · Primary source

    Post-Mortem / Root Cause Analysis (April 2021) ↗

    Reviewed 2026-10-02