Follow

registry.coder.com/
Coder registry compromise pushed malicious Terraform modules Attackers breached Coder’s Cloudflare-backed registry infrastructure and added unauthorized servers to the pool serving registry.coder.com , causing some users between 07:35 and 21:45 UTC on August 31 to receive modified Terraform modules with credential-stealing code. Coder’s advisory says the payload targeted environment secrets, API keys, CI/CD credentials, OIDC tokens, SSH keys, terminal history

· · lailagislason · 0 · 0 · 0
Sign in to participate in the conversation
Mastodon

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!