Monday.com says its source code was hit in recent cyberattack

Hacker
Image Credit: Geralt / Pixabay (Image credit: Image Credit: Geralt / Pixabay)

Online collaboration tool Monday.com has acknowledged that cybercriminals accessed a read-only copy of its source code.

Monday.com is an project management platform that counts the likes of Uber, BBC Studios, Adobe, Universal, Hulu, L'Oreal, Coca-Cola, and Unilever as customers.

The platform is one of a growing list of targets that has fallen prey to a supply-chain attack on software auditing company Codecov last month.

TechRadar needs you!

We're looking at how our readers use VPN for a forthcoming in-depth report. We'd love to hear your thoughts in the survey below. It won't take more than 60 seconds of your time.

>> Click here to start the survey in a new window<<

Unauthorized users modified Codecov’s bash uploader script and used it for several months to siphon off credentials of its customers, one of them being Monday.com. 

“While we have seen evidence that our source code was accessed due to the Codecov vulnerability, to date, we have found no evidence of any unauthorized modifications to our source code, or any impact on our products,” wrote Monday.com in a blog post last week, outlining their response to the Codecov incident.

The company was forced to reveal the news in documents filed with the U.S. Securities and Exchange Commission (SEC) as it prepares a stock exchange listing in the country.

Supply chain victims

Monday.com is just one in the string of Codecov customers that has been compromised by the Codecov attackers in typical supply-chain attack fashion.

Last month, an anonymous investigator from the FBI's San Francisco office told Reuters that the Codecov attackers put extra effort to break into the software auditing company that has thousands of customers, in order to infiltrate other “makers of software development programs” as well as companies that themselves provide many customers with technology services. 

In addition to Monday.com, reports suggest that cybersecurity firm Rapid7, software developers HashiCorp, cloud communications platform Twilio, cloud services provider Confluent, and insurance company Coalition, have all been affected by the Codecov breach in some way.  

Via BleepingComputer

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
Data Breach
Thousands of widely-used public workspaces are leaking data
Representational image depecting cybersecurity protection
Top venture capital firm Insight Partners confirms it was hit by cyberattack
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring