Supply chain

Coder platform targeted by attackers delivering malicious Terraform modules

Digital warning sign on circuit board with glitch effect. Alert system error, data breach, cybersecurity threat, urgent issue notification. Red warning light indicates critical danger.

Coder, a platform used by prominent government and private organizations to provide developers with secure, self-hosted cloud development environments, has disclosed a security incident where attackers compromised its Cloudflare infrastructure. The attackers added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code, with further coverage provided by Bleeping Computer.

The attack occurred between 07:35 UTC and 21:45 UTC on Monday, August 31. Attackers gained access to Coder's Cloudflare infrastructure and inserted unauthorized IP addresses into the module registry's server pool. This redirection caused a subset of users to receive malicious Terraform modules instead of legitimate ones. These compromised modules were designed to steal sensitive information, including provisioner environment variables, cloud infrastructure API keys, CI/CD credentials, configuration secrets, and SSH keys. The stolen data was exfiltrated to the domain coder-infra[.]com.

Coder recommends that affected users rotate all potentially compromised secrets and examine network logs for connections to the malicious domain. While Coder has released patched versions of its software, it cannot definitively identify all compromised deployments due to the attacker's infrastructure being outside its control.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds