:

CODER'S REGISTRY HACKED TO DISTRIBUTE MALWARE

INDUSTRY DESK1 MIN READ
THU, SEP 3, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Attackers compromised Coder's Cloudflare infrastructure and injected malicious Terraform modules designed to steal credentials. The unauthorized registry servers delivered the infected packages to users.

The attackers gained access to Coder's infrastructure and added rogue registry servers to the system. These servers pushed compromised Terraform modules containing credential-stealing code to unsuspecting users downloading packages. Terraform modules are widely used for infrastructure-as-code deployments, making this a significant supply chain attack vector. Users who downloaded affected modules during the compromise window may have exposed sensitive credentials and authentication tokens. The breach highlights risks in dependency chains and the importance of verifying package sources. Coder has secured its infrastructure and notified affected users to rotate credentials and check for unauthorized access. Infrastructure-as-code tools have become increasingly targeted by threat actors due to their access to sensitive deployment credentials and cloud environments.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

A US senator has called on the NSA to provide official guidance on virtual private network selection and usage, citing confusion over the growing array of available options.

2H AGOIndustry Desk

Utah will not enforce its groundbreaking VPN age-verification law while a legal challenge proceeds through the courts. The state became the first to target VPN usage alongside broader age-verification requirements.

2H AGOIndustry Desk

A critical vulnerability in Elementor Pro for WordPress is being actively exploited to inject webshells and execute arbitrary commands on compromised servers. The flaw, tracked as CVE-2026-32475, has been patched but attackers are already targeting unpatched installations.

7H AGOSecurity Desk

Passwords found in infostealer logs represent just one piece of a larger breach. Attackers gain access to authenticated sessions that can bypass multi-factor authentication, creating immediate account takeover risks.

8H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.