Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials

A critical security incident at Coder exposed users of its Terraform module registry to malicious packages designed to steal credentials from cloud development environments. The attack involved unauthorized changes to Coder’s Cloudflare infrastructure, allowing an unidentified threat actor to redirect some registry traffic to attacker-controlled servers. According to Coder’s security advisory, the attacker added unauthorized […]

This article has been indexed from Cyber Security News

Read the original article: