Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications.
The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government, and defense companies.
Earlier this week, Coder disclosed that an attacker targeted registry.coder.com, the project's package-hosting site that developers use to source components for their workspace templates.
Although Coder's registry runs behind Cloudflare, the attacker accessed its underlying infrastructure and added unauthorized servers to the registry's pool.
As a result, Cloudflare routed some registry requests to the attacker’s servers, instead of Coder’s legitimate servers, delivering malicious files to a subset of users.
“An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry,” reads Coder’s advisory.
“These unauthorized IP addresses hosted a version of Coder’s registry that contained artifacts which included malicious code.”
The project said that the delivery window for the malicious artifacts was between 07:35 UTC and 21:45 UTC on Monday, August 31.
During this time, the malicious servers delivered modified versions of Terraform modules, which are ready-made bundles of instructions for creating and configuring computing infrastructure.
... continue reading