Bash Uploader Identity-based compromise

25 views
Skip to first unread message

Gavin Hindman

unread,
Apr 15, 2021, 12:34:34 PM4/15/21
to ossf-wg-developer-identity
Another identity-based supply chain attack for review:

"On Thursday, April 1, 2021, we learned that someone had gained unauthorized access to our Bash Uploader script and modified it without our permission. The actor gained access because of an error in Codecov’s Docker image creation process that allowed the actor to extract the credential required to modify our Bash Uploader script."


Reply all
Reply to author
Forward
0 new messages