As cited
Copy frozen at (site build).
breaches incidents
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and inserted malicious registry servers to distribute Terraform modules containing credential-stealing code. The attack targeted the infrastructure used to deliver these modules to downstream users.
Why it matters: Organizations using Coder's Terraform modules are at immediate risk of credential theft if they pulled affected versions; practitioners should audit their module consumption and verify the integrity of deployed infrastructure code.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and inserted malicious registry servers to distribute Terraform modules containing credential-stealing code. The attack targeted the infrastructure used to deliver these modules to downstream users.
Why it matters: Organizations using Coder's Terraform modules are at immediate risk of credential theft if they pulled affected versions; practitioners should audit their module consumption and verify the integrity of deployed infrastructure code.
- Source published
- First seen by Cybersecurity Tracker