[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f9NXFMweREL3eQfZ7LUnHxzAzFutzhU6lNvPLfUMIGh0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"a48a7827-412a-4e8d-a496-39cddb598ec5","compromised-registry-infrastructure-delivers-credential-stealing-terraform-modules","ea0d0b83-afd6-4981-a48f-44108f8cbbc8","Compromised Registry Infrastructure Delivers Credential-Stealing Terraform Modules","Attackers gained unauthorized access to Coder's Cloudflare infrastructure and injected malicious servers into its module registry, turning a trusted software distribution channel into a credential-theft vector. This is a classic supply chain attack: users who believed they were consuming legitimate Terraform modules were instead executing code designed to exfiltrate API keys, CI\u002FCD secrets, and other sensitive credentials. The incident highlights how a single point of compromise in a trusted registry can cascade across every downstream user and pipeline. Stolen credentials from CI\u002FCD systems are especially dangerous because they can grant persistent, broad access to production environments long after the initial breach. Organizations must treat third-party module registries as untrusted until integrity is verified.","**Immediate actions:**\n- Rotate all API keys, CI\u002FCD credentials, and secrets that may have been present in environments consuming Coder modules between August 31–September 1, 2026.\n- Audit all Terraform module sources in use and pin dependencies to verified, cryptographically signed versions or known-good commit hashes.\n- Scan CI\u002FCD pipeline logs for any outbound connections to `coder-infra[.]com` or other anomalous domains.\n\n**Long-term improvements:**\n- Implement artifact integrity verification (e.g., checksum validation, code signing) for all third-party modules and dependencies before use in pipelines.\n- Enforce least-privilege access controls on infrastructure management platforms (e.g., Cloudflare) using MFA, short-lived tokens, and strict role separation.\n- Store CI\u002FCD secrets in a dedicated secrets manager with automated rotation and access auditing rather than embedding them in pipeline configurations.\n\n**Detection measures:**\n- Deploy egress filtering and DNS monitoring in CI\u002FCD environments to alert on connections to unexpected or newly registered domains.\n- Enable real-time alerting on unauthorized changes to registry configurations, DNS records, or infrastructure provider settings.\n- Integrate Software Composition Analysis (SCA) tooling into pipelines to detect unexpected or tampered modules before execution.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 6: Access Control Management","CIS Control 13: Network Monitoring and Defense","NIST SP 800-161: Supply Chain Risk Management","NIST AC-2: Account Management","NIST AC-6: Least Privilege","NIST SI-7: Software, Firmware, and Information Integrity","NIST SR-4: Provenance","NIST IR-6: Incident Reporting","SLSA Supply Chain Levels for Software Artifacts (Level 3+)","GDPR Article 32: Security of Processing","GDPR Article 33: Notification of a Personal Data Breach","published","2026-09-03T22:20:41.518961+00:00","2026-09-03T22:20:41.411+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcoders-registry-infrastructure-compromised-to-push-malicious-modules\u002F","coder-s-registry-infrastructure-compromised-to-push-malicious-modules-25f09a","Coder's registry infrastructure compromised to push malicious modules",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":40,"name":41,"slug":42,"description":43,"color":44},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":46,"name":47,"slug":48,"description":49,"color":50},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]