The FBI has warned that cybercriminals are exploiting SonarQube applications misconfigured to steal source code repositories from US government agencies and businesses .

The attacks have been systematic since April 2020, the FBI said on its website.
The FBI's warning is aimed at owners of SonarQube, a web application that companies integrate into their "software build chains" to test source code and discover security before releasing code and applications.
SonarQube applications are installed on web servers and connected to source code hosting systems, such as BitBucket, GitHub, GitLab accounts or Azure DevOps systems
However, according to the FBI, some government agencies and companies have left these systems unprotected, running default configuration (on port 9000) and with default admin credentials (admin/admin).
The FBI says hackers are exploiting this configuration to gain access to SonarQube apps, which allows them to gain access to the associated source code repositories. In this way, they are able to break in and steal private/sensitive applications and information.
Security experts provided details about two such breaches that took place in recent months:
“In August 2020, unknown hackers exposed internal data from two organizations via a public lifecycle repository tool. The stolen data came from SonarQube apps that used default settings and admin credentials.“.
Elsewhere they say: “This activity is similar to a previous data breach, which took place in July 2020, in which a criminal (who has been identified) extracted source code from businesses via insecure SonarQube apps and published that source code to a public repository.”
This FBI warning addresses a well-known issue for software developers and security experts.

In most cases, there are warnings about the risks of unprotected MongoDB or Elasticsearch databases (e.g. exposed databases on the internet without passwords), but there has been no particular emphasis on SonarQube.
However, some security researchers have been warning about the dangers of exposed SonarQube apps with default credentials since May 2018.
At the time , analyst Bob Diachenko said that about 30%-40% of all SonarQube apps (~3,000) available online did not have a password or authentication mechanism enabled.
This year, a Swiss security researcher named Till Kottmannalso raised the same issue. Over the course of the year, Kottmann has been collecting source code from dozens of technology companies on a public portal. In many cases, this source code came from SonarQube apps.
"Most people seem to change absolutely none of the settings in SonarQube," Kottmann told ZDNet.
“I don’t know the current number of exposed SonarQube apps. I’m guessing there are still well over 1,000 servers that are ‘vulnerable’ either due to a lack of an authentication mechanism or default credentials,” he said.
According to the FBI, government agencies and businesses should take some steps to protect their SonarQube servers . Some of these are:
- Change default settings
- Change default credentials
- Use a firewall to prevent unauthorized access to the application
