Written By Muhammad Abdullah

Background on Codecov

Before submitting their source code to clients, developers may find flaws using the automatic code review tool Codecov. Both government organizations like NASA and software firms like IBM and Atlassian often utilize the platform.

Details of the Data Breach

Codecov announced on April 15th, 2021, that an unauthorized actor had gained access to their Bash Uploader script, giving them access to private client information such as API tokens, passwords, and user keys.

Our analysis revealed that these systems had been breached over three months beginning on January 31st, 2021, by attackers. While it is thought that they had access to client data during this period, there has been no proof so far that any of it was stolen or used improperly.

Investigations into the Incident

Security investigators have been aggressively attempting to determine the breadth of the breach since it was discovered and to comprehend what data the attackers may have obtained.

Interviewing witnesses and examining logs from both Codecov’s systems and those of third-party services they connect with have been necessary for this (such as cloud hosting providers).

Investigators are still looking, but thus far they have not found any proof of unauthorized behavior or abuse of client data.

April Satter Reuters Reports on Investigation

Reuters released a report outlining some of their investigation’s findings on the event on April 23rd, 2021.

The attacker “had gained full access to certain parts of [Codecov’s] computing infrastructure for more than three months and could have potentially exfiltrated large amounts of sensitive data or planted malicious code without detection,” according to their sources in the internal security team at Codecov.

Moreover, they revealed that security teams at both Codecov and the third-party services they use had been investigating other potential entry points for attackers that Codecov has discovered (such as cloud hosting providers).

Impact on Customers

Several clients who depend on Codecov’s services for automated code reviews and testing before deploying new software versions into production settings are concerned about the issue.

Quick to make announcements notifying consumers of the actions they were taking in reaction to the incident, companies including IBM and Atlassian (e.g., reviewing credentials associated with their accounts).

Parallel to this, it has been stated that federal organizations like NASA are evaluating all current contracts made with Codecov and temporarily halting new ones till further notice while they investigate any security holes in their systems that may have been revealed by this event.


