Page 7 - Shell Scripting News Today : Breaking News, Live Updates & Top Stories | Vimarsana

Stay updated with breaking news from Shell scripting. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.

Top News In Shell Scripting Today - Breaking & Trending Today

Hacked Codecov uploading script leaked creds for two months


By
Juha Saarinen
on Apr 20, 2021 12:14PM
Scores of projects potentially affected by supply chain attack.
A malicious alteration to a shell script lay undetected since January this year at software testing coverage report provider Codecov, sparking fears of another significant supply chain attack.
Forensic analysis shows that an unknown threat actor exploited an error in Codecov s Docker container image creation process, and gained access to the credential that allowed the modification to the company s Bash Uploader script.
Codecov said a Google Cloud Storage key was accessed starting January 31 this year, and not secured until April 1 US time.
The script is normally used to upload coverage reports to Codecov, but it was altered to transmit the UNIX shell environment, which can be used to store variables. ....

United States , Florian Roth , Codecov Bitrise , Bash Uploader , Google Cloud Storage , Shell Scripting , ஒன்றுபட்டது மாநிலங்களில் , புளோரியன் ரோத் , கூகிள் மேகம் சேமிப்பு , ஷெல் ஸ்கிரிப்டிங் ,