Coder's registry infrastructure compromised to push malicious modules

Executive Summary

Attackers hijacked Coder’s Cloudflare infrastructure, inserting unauthorized registry servers that served malicious Terraform modules. The modules contained credential‑stealing code, enabling attackers to harvest secrets from users’ environments. The compromise highlights the risk of third‑party registry services and the need for stricter access controls.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-03T20:04:24+00:00 - Category: threat-intel

Original Description: Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]

"Kindness is the language which the deaf can hear and the blind can see."

— Mark Twain
Source: Bleeping Computer