Coder Registry Hacked via Cloudflare to Deliver Credential-Stealing Terraform Modules
Attackers gained unauthorized access to Coder's Cloudflare configuration and inserted a malicious server into the module registry's delivery pool, causing some users to receive tampered Terraform modules. The malicious modules were designed to search for credentials in the execution environment and exfiltrate them to an attacker-controlled domain, coder-infra[.]com. Compromise could occur during routine operations such as template imports, updates, dry runs, or workspace builds, and cached modules extend the window of potential exposure beyond the initial incident period. Coder has published a security advisory, GHSA-vx42-ghc9-gw65, including SQL queries to help administrators detect signs of malicious module execution in provisioner job logs. Affected organizations are advised to audit fetched modules within the target timeframe, clear caches, and rotate any secrets accessible from impacted provisioner environments.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in