Hackers Hijack Coder Module Registry to Distribute Credential-Stealing Malicious Packages
4 Articles
4 Articles
Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials
A critical security incident at Coder exposed users of its Terraform module registry to malicious packages designed to steal credentials from cloud development environments. The attack involved unauthorized changes to Coder’s Cloudflare infrastructure, allowing an unidentified threat actor to redirect some registry traffic to attacker-controlled servers. According to Coder’s security advisory, the attacker added unauthorized […]
Hackers Hijack Coder Module Registry to Distribute Credential-Stealing Malicious Packages
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic to attacker-controlled infrastructure. This led to the temporary distribution of tampered Terraform modules intended to steal credentials. The incident affected the registry at registry.coder.com on August 31, 2026, between 07:35 UTC and
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium




