Hackers Hijack Coder Module Registry to Distribute Credential-Stealing Malicious Packages
Coder's official package registry was briefly hijacked to serve fake Terraform modules that steal cloud account passwords. Attackers redirected some users to their own servers to push malicious code.
- Severity
- Not scoredNo CVSS score recorded
How it works
- Attackers hijacked Coder's official package registry to redirect some users to their own servers.
- They uploaded fake Terraform modules that secretly sent stolen cloud account passwords back to their servers.
- This only worked for users who installed the fake modules from the hijacked registry.
What to do
Check if you installed Terraform modules from Coder's registry between the hijack and the fix. Look for any modules installed or after the hijack date (not yet public) but before the registry was restored. If you used Coder's registry during that time, assume you may have installed malicious modules.
Stop using the hijacked registry immediately. Only install modules from Coder's official registry after it was restored. Remove any suspicious modules you may have installed during the hijack. Check your cloud accounts for unauthorized access and change any passwords used with Terraform.
Technical details
Coder has reported a significant software supply chain incident in which an unidentified threat actor redirected part of its official module registry traffic to attacker-controlled infrastructure. This led to the temporary distribution of tampered Terraform modules intended to steal credentials.