Coder Registry Compromised, Malicious Terraform Modules Distributed Via Supply‑Chain Attack
Coder, a platform that hosts a public module registry for infrastructure‑as‑code tools, disclosed a supply‑chain breach that allowed attackers to serve altered Terraform modules to unsuspecting users.
The intrusion was discovered after the company noticed that a portion of traffic to its registry was being rerouted to servers under the control of an unknown threat actor. During the brief window of redirection, the malicious infrastructure delivered tampered packages that appeared identical to legitimate Terraform modules but were embedded with code designed to harvest credentials.
Terraform, an open‑source tool from HashiCorp, automates the provisioning of cloud resources. Because many organizations rely on shared modules to standardise infrastructure, any compromise in the module supply chain can cascade into widespread credential exposure across multiple cloud accounts.
Coder’s security team acted quickly to shut down the rogue traffic and remove the compromised modules from the registry. The company issued an advisory urging users to verify the integrity of any modules downloaded during the incident window and to rotate any credentials that may have been exposed.
Supply‑chain attacks have risen sharply in recent years, with high‑profile cases such as the SolarWinds compromise and the malicious npm packages that stole npm tokens highlighting the risk. Experts note that attackers increasingly target the distribution channels of developer tools, exploiting the trust placed in official repositories to gain footholds in otherwise secure environments.
While the exact motives and identity of the actors remain unknown, the episode underscores the importance of robust verification mechanisms, such as cryptographic signing of packages and the use of reproducible builds. Coder has pledged to implement additional safeguards, including stricter traffic monitoring and mandatory signature verification for future module releases, to reduce the likelihood of a repeat breach.
Comments (0)
Be the first to comment.
Join the discussion