← Back to Feed

Coder's registry infrastructure compromised to push malicious modules

September 3, 2026 · BleepingComputer · Severity: MEDIUM

Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.

Key Takeaways

  • A coder's registry infrastructure was compromised to push malicious modules to unsuspecting developers.
  • The supply chain attack targets the software development ecosystem by injecting malware into legitimate packages.
  • Developers should verify package integrity and monitor for unexpected updates in their dependency chains.
☕ Buy a Coffee