Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure to distribute malicious Terraform modules designed to steal credentials.

The popular platform Coder has suffered a major security breach affecting its infrastructure. Attackers successfully compromised the company's Cloudflare setup and introduced unauthorized registry servers into the system.
Through these unauthorized servers, threat actors distributed malicious Terraform modules. The injected code was specifically designed to execute credential-stealing operations without the users' knowledge.
Cybersecurity experts emphasize that supply chain attacks of this nature pose severe risks to modern software development. Attackers frequently exploit the inherent trust developers place in standard modules and registries.
This incident serves as a critical wake-up call for IT professionals and development teams globally, including the tech community in Uzbekistan. Securing cloud infrastructure and rigorously auditing third-party dependencies are more crucial than ever.
Remediation efforts are currently underway to secure the affected systems and purge the malicious components. Users are advised to review and verify all recently used Terraform modules immediately.



