← Back to Feed
Coder's registry infrastructure compromised to push malicious modules
September 3, 2026 · BleepingComputer · Severity: MEDIUM
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
Key Takeaways
- A coder's registry infrastructure was compromised to push malicious modules to unsuspecting developers.
- The supply chain attack targets the software development ecosystem by injecting malware into legitimate packages.
- Developers should verify package integrity and monitor for unexpected updates in their dependency chains.