Toutes les vulnérabilités
HIGHSupply chainexploited in the wildcurated

SC-CODECOV-BASH-UPLOADER-2021

CI/CD · Codecov Bash Uploader

Résumé

Codecov is a code-coverage tool wired into the CI pipelines of about 29,000 organisations. On 31 January 2021, attackers extracted a Google Cloud Storage key from an error in Codecov's Docker image and used it to quietly alter Codecov's "Bash Uploader," the script customers pipe into their CI to upload coverage reports. For two months, undetected, that tampered script copied the secrets and git repository URLs out of every CI environment it ran in, the AWS keys, deploy keys, API tokens, and passwords sitting in build environment variables, and sent them to the attackers. It is the canonical lesson in the danger of piping a remote script into your shell, and in how one tool's compromise harvests thousands of downstream secrets.

How it happened

Codecov distributed its uploader as a Bash script that customers ran in CI, very often with the pattern curl ... | bash, piping a remote script straight into the shell. That convenience was the weakness. Attackers obtained a credential (an HMAC key for a Google Cloud Storage service account) exposed in an intermediate layer of Codecov's self-hosted Docker image, and used it to modify the uploader script where it was actually served from, a Google Cloud Storage bucket.

From 31 January, the altered script did its normal job and one extra thing: a single added line, buried in the 1,800-line script, scooped up the secrets in the CI environment (every environment variable, including AWS IAM keys, deploy keys, API keys, service-account credentials, tokens, and passwords) plus the git remote origin URLs (which let the attackers reach private source repositories), and exfiltrated them to an attacker-controlled server. Because customers were piping the live script straight into a shell, they ran whatever Codecov served, and the same compromised uploader was also bundled into Codecov's GitHub Action, CircleCI Orb, and Bitrise Step, so many victims never ran curl | bash directly. It is a supply-chain attack on the CI toolchain, and it ran undetected for roughly two months until a customer noticed the script's checksum did not match the hash Codecov published.

The damage

Codecov has about 29,000 customers, and more than 23,000 were reported affected, so the harvested secrets were keys to thousands of other companies' cloud accounts, code repositories, and services; the real damage was the second-order breaches they enabled. Named downstream victims included HashiCorp (whose exposed GPG signing key, used to sign its own product releases, had to be rotated), Rapid7 and Monday.com (source code accessed), and Twilio. Reuters reported the attackers used automation to pivot into hundreds of customer networks, which drew a federal investigation. Coming only weeks after SolarWinds, it reinforced the same uncomfortable truth: a single trusted tool sitting in everyone's pipeline is a master key to thousands of environments.

Why Codecov still matters

Codecov leaves two durable lessons. First, curl | bash is dangerous: piping a remote script into your shell means you execute whatever the server serves at that moment, including a tampered version, so verify integrity with a checksum, signature, or SRI, or vendor a pinned, reviewed copy. Second, CI secrets are gold: build environments hold the credentials to everything, so scope them to least privilege, rotate them fast on any tooling compromise, and restrict CI runner egress so a poisoned tool cannot quietly phone the secrets home. It is a sibling of SolarWinds in the 2020-21 supply-chain reckoning that made CI/CD security a first-class concern.

Comment le corriger

  • Assume every secret exposed to the tampered uploader is compromised: rotate all CI credentials, cloud keys, and tokens immediately.
  • Pin and integrity-verify the uploader, and any CI tooling, going forward, and hunt for unauthorized use of the exposed credentials.
  • Review CI logs and cloud audit trails for attacker activity using the stolen secrets.

Comment l’éviter

  • Verify the integrity (checksum, GPG signature, or SRI) of any uploader or installer script before executing it.
  • Avoid piping remote scripts straight into a shell (curl | bash) in CI; vendor and pin a reviewed copy.
  • Scope CI secrets to least privilege and rotate them on any uploader or tooling compromise.
  • Restrict and monitor CI runner egress so a poisoned tool cannot exfiltrate environment variables.
  • Pin third-party tooling to a known-good version and watch for unexpected upstream changes.

Références

Vulnérabilités liées

Tout Supply chain →