Coder's registry infrastructure compromised to push malicious modules

Summary

Attackers compromised the registry infrastructure of Coder, a company providing development environments, by gaining access to their Cloudflare account. They then inserted malicious Terraform modules designed to steal credentials, which were distributed to users of Coder's registry.

IFF Assessment

FOE

The compromise of Coder's infrastructure and the distribution of credential-stealing modules represent a direct threat to user security and account integrity.

Defender Context

This incident highlights the risk of supply chain attacks targeting development infrastructure. Defenders should be vigilant about the integrity of third-party modules and services used in their development pipelines, and implement strong access controls for infrastructure providers like Cloudflare.

Read Full Story →