Feed›Network & Infrastructure›Coder's registry infrastructure compromised to push maliciou...
Network & InfrastructureBleeping Computer
9.0 — CRITICAL

Coder's registry infrastructure compromised to push malicious modules

📅 3 September 2026 at 20:04 UTC📰 Bleeping ComputerView original source ↗
Coder's registry infrastructure compromised to push malicious modules

Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A malicious actor compromised Coder's Cloudflare infrastructure, adding unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code to a subset of users.

⚙️Technical Details
Affected Systems
registry.coder.com
Attack Vectors
Cloudflare routingUnauthorized IP addresses added to the registry's pool
💥Impact Assessment
Severity: critical
Who Is at Risk
Users of Coder's module registryOrganizations using Coder's platformSeverity: critical
🛡️Recommended Actions
1Rotate all impacted secrets as soon as possible
2Examine firewall, proxy, DNS, and VPC flow logs for connections to coder-infra[.]com
3Search provisioner logs for data.external.telemetry and purge potentially malicious cached packages
📦Affected Products
Coder's module registry

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed