bleeping-computer · Crawled Sep 4, 2026

Coder's registry infrastructure compromised to push malicious modules

1 IoCs
Read original article ↗

AI Summary

Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers to distribute malicious Terraform modules. These modules contained credential-stealing code that targeted environment variables, API keys, CI/CD credentials, SSH keys, and other sensitive data from development environments. The malicious activity occurred between 07:35 UTC and 21:45 UTC on August 31, 2026, with stolen data exfiltrated to the domain coder-infra[.]com. Coder recommends rotating secrets, inspecting logs for connections to the suspicious domain, and purging potentially compromised cached modules.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain coder-infra[.]com Details →