The injection of malicious code into the Codecov script compromised the HashiCorp PGP key.
HashiCorp, known for developing open tools like Vagrant, Packer, Nomad, and Terraform, announced a leak of a private GPG key used for creating digital signatures that verify releases. Attackers who gained access to the GPG key could potentially make hidden changes to HashiCorp products, certifying them with a valid digital signature. The company stated that during the audit conducted, traces of such modification attempts were found […]
