Codecov Supply-Chain Attack Hacked
Summary
A software company specializing in auditing tools suffered an attack over the course of the the past four months and disclosed this month. Several news outlets have reported on the attack and the vulnerability used to exploit a zero-day vulnerability.
Threat Type
Vulnerability, Breach
Overview
An investigation by Codecov led to the discovery of a supply-chain attack that has been occurring since January 2021. The maker of auditing tools stated a threat actor had modified Bash Uploader script and exp