Coder's registry infrastructure compromised to push malicious modules
Summary
Attackers compromised the registry infrastructure of Coder, a company providing development environments, by gaining access to their Cloudflare account. They then inserted malicious Terraform modules designed to steal credentials, which were distributed to users of Coder's registry.
IFF Assessment
FOE
The compromise of Coder's infrastructure and the distribution of credential-stealing modules represent a direct threat to user security and account integrity.
Defender Context
This incident highlights the risk of supply chain attacks targeting development infrastructure. Defenders should be vigilant about the integrity of third-party modules and services used in their development pipelines, and implement strong access controls for infrastructure providers like Cloudflare.