Coder's registry infrastructure compromised to push malicious modules
Coder's Cloudflare infrastructure compromised, delivering malicious Terraform modules containing credential-stealing code.
Intelligence analysis by Qwen 2.5 (3B)

An attacker gained access to Coder's Cloudflare infrastructure, adding unauthorized registry servers that delivered malicious Terraform modules to users.
A bad person got into a company's computer system and added fake servers that sent out bad software. This software tried to steal passwords from people's computers.
Analysis
{"heading_1":"The Attack","paragraph_1":"Coder does not have access to crucial logs and cannot conclusively identify every compromised deployment, but the attacker's infrastructure is outside the project's control.","paragraph_2":"The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments, showing that once attackers have valid credentials, prevention drops sharply.","paragraph_3":"The attacker's infrastructure is outside the project's control, and the Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments, showing that once attackers have valid credentials, prevention drops sharply.","heading_2":"Impact and Recommendations","heading_3":"Prevention and Detection"}
Key points
- Unauthorized servers added to Coder's registry infrastructure by an attacker.
- Malicious Terraform modules delivered to users, containing credential-stealing code.
- Users are advised to rotate impacted secrets and examine logs for suspicious activity.
Developers can take steps to protect their systems by rotating passwords and checking logs for suspicious activity.
If the attacker had valid credentials, they could potentially cause more damage, and it's hard to know exactly how many systems were affected.



