A critical security incident at Coder exposed users of its Terraform module registry to malicious packages designed to steal credentials from cloud development environments. The attack involved unauthorized changes to Coder’s Cloudflare infrastructure, allowing an unidentified threat actor to redirect some registry traffic to attacker-controlled servers. According to Coder’s security advisory, the attacker added unauthorized […]
Read the original article: