Coder's Registry Compromised to Distribute Malicious Terraform Modules
Article Content
On August 31, 2026, Coder's Cloudflare infrastructure was compromised by an unidentified actor who added unauthorized IP addresses to the module registry. This led to the delivery of malicious Terraform modules containing credential-stealing code to users. The attack targeted users who downloaded modules between 07:35 UTC and 21:45 UTC on that day. The malicious code aimed to exfiltrate sensitive information such as API keys and configuration secrets to a lookalike domain, coder-infra.com. Coder has advised affected users to review their deployment logs and clear any cached packages. No evidence suggests that customer data maintained by Coder was compromised. Users are urged to rotate any impacted secrets and follow the provided remediation steps. The incident highlights vulnerabilities in the infrastructure despite protections like Cloudflare.
Key Points: • Unauthorized IP addresses were added to Coder's module registry, delivering malicious modules. • The attack window was between 07:35 UTC and 21:45 UTC on August 31, 2026. • Users are advised to review logs and purge potentially malicious cached packages.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.