Network & InfrastructureBleeping Computer
9.0 — CRITICAL
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A malicious actor compromised Coder's Cloudflare infrastructure, adding unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code to a subset of users.
⚙️Technical Details
Affected Systems
registry.coder.com
Attack Vectors
Cloudflare routingUnauthorized IP addresses added to the registry's pool
💥Impact Assessment
Severity: critical
Who Is at Risk
Users of Coder's module registryOrganizations using Coder's platformSeverity: critical
🛡️Recommended Actions
1Rotate all impacted secrets as soon as possible
2Examine firewall, proxy, DNS, and VPC flow logs for connections to coder-infra[.]com
3Search provisioner logs for data.external.telemetry and purge potentially malicious cached packages
📦Affected Products
Coder's module registry
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
