There was that one time everyone who used codecov.io sent their AWS secrets etc. to an unknown third party because they followed codecov.io’s instructions to pipe cURL into Bash in their continuous integration workflow and someone snuck a back door into the endpoint. It was also vulnerable to a man-in-the-middle attack even before that. Pipes are kind of magical!

1 Like