<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Coder's registry infrastructure compromised to push malicious modules]]></title><description><![CDATA[<p dir="auto">Attackers gained access to Coder’s Cloudflare-backed infrastructure and inserted unauthorized registry servers that distributed malicious Terraform modules designed to steal credentials. The compromised modules were served to developers who pulled from Coder’s public registries during a targeted window, with the tampered code executed locally when Terraform initialized the modules.</p>
<p dir="auto">The incident highlights a supply-chain risk in infrastructure-as-code workflows — the malicious modules were not flagged by typical signature checks, as the attackers abused legitimate registry endpoints. Organizations that used Coder’s registry during the exposure period should treat any downloaded modules as potentially untrusted and audit recent Terraform state and plan outputs.</p>
<ul>
<li>Review any Terraform modules fetched from Coder’s registry for unexpected submodules or remote <code>data</code> sources.</li>
<li>Rotate cloud provider credentials, API keys, and any secrets that may have been exposed to the local environment during module execution.</li>
<li>Inspect shell history and logs for suspicious outbound connections or newly created background processes on developer workstations.</li>
<li>Re-run dependency and module integrity checks against known-good hashes if available from your own internal mirror.</li>
</ul>
<p dir="auto">No specific CVE identifier was disclosed in the report, and the exact duration of the compromise has not been published.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Has your team audited Terraform module integrity after this disclosure, or are you relying on registry-side verification alone?</p>
]]></description><link>https://xploitlk.com/topic/205/coder-s-registry-infrastructure-compromised-to-push-malicious-modules</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:30 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/205.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 03 Sep 2026 20:30:25 GMT</pubDate><ttl>60</ttl></channel></rss>