Coder's Registry Compromised to Distribute Malicious Terraform Modules

Coder's Registry Compromised to Distribute Malicious Terraform Modules

First seen 4 Sep 2026, 00:59 UTC Bleepingcomputergithub.com 73.2

Article Content

Browse articles
ThreatCluster

On August 31, 2026, Coder's Cloudflare infrastructure was compromised by an unidentified actor who added unauthorized IP addresses to the module registry. This led to the delivery of malicious Terraform modules containing credential-stealing code to users. The attack targeted users who downloaded modules between 07:35 UTC and 21:45 UTC on that day. The malicious code aimed to exfiltrate sensitive information such as API keys and configuration secrets to a lookalike domain, coder-infra.com. Coder has advised affected users to review their deployment logs and clear any cached packages. No evidence suggests that customer data maintained by Coder was compromised. Users are urged to rotate any impacted secrets and follow the provided remediation steps. The incident highlights vulnerabilities in the infrastructure despite protections like Cloudflare.

Key Points: • Unauthorized IP addresses were added to Coder's module registry, delivering malicious modules. • The attack window was between 07:35 UTC and 21:45 UTC on August 31, 2026. • Users are advised to review logs and purge potentially malicious cached packages.

Ask AI about this cluster

Timeline

2026-08-31
Unauthorized access to Coder's infrastructure
An unidentified actor compromised Coder's Cloudflare infrastructure, adding unauthorized servers to the registry's pool.
Bleepingcomputer
2026-08-31
Malicious modules delivered
Malicious Terraform modules containing credential-stealing code were served to users during the attack window.
Bleepingcomputer
2026-09-04
Coder issues advisory
Coder published an advisory detailing the incident and recommended steps for affected users to verify and mitigate exposure.
github.com