Coder’s registry infrastructure compromised to push malicious modules

Coder’s registry infrastructure compromised to push malicious modules
Attackers compromised Coder’s Cloudflare infrastructure and redirected some registry traffic to unauthorized servers that served malicious Terraform modules. The malicious code stole credentials and secrets from affected environments and exfiltrated them to coder-infra[.]com. #Coder #Cloudflare #Terraform #coder-infra

Keypoints

  • Attackers gained access to Coder’s Cloudflare infrastructure.
  • Unauthorized servers were added to the Coder registry pool.
  • Some users received malicious Terraform modules instead of legitimate ones.
  • The modules stole secrets, API keys, credentials, and tokens from infected hosts.
  • Potentially impacted users should rotate secrets and review logs for coder-infra[.]com.

Read More: https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/