Coder's module registry hijacked to serve credential-stealing Terraform modules
An attacker added rogue servers to Coder's Cloudflare pool, routing some registry requests to malicious copies.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code, BleepingComputer reported. Coder provides self-hosted cloud development environments used by organizations including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government and defense companies. Earlier this week Coder disclosed that an attacker targeted registry.coder.com, the package-hosting site developers use to source components for workspace templates. Although the registry runs behind Cloudflare, the attacker gained access to the underlying infrastructure and added unauthorized IP addresses to the pool used for the module registry. As a result, Cloudflare routed some registry requests to the attacker's servers instead of Coder's legitimate ones, delivering malicious files to a subset of users. Coder's advisory said an unidentified malicious actor gained access to its Cloudflare infrastructure and that the unauthorized addresses hosted a version of the registry containing modified modules. The incident matters because workspace templates are executed to build developer environments, so a tampered module can harvest secrets from the machines and accounts that developers rely on. Organizations using Coder should review which modules were pulled during the affected period and rotate any credentials that may have been exposed.