Coder’s registry compromised to distribute malicious Terraform modules
Attackers breached Coder's Cloudflare infrastructure to push malicious Terraform modules that embed credential-stealing code, threatening developer credentials.
Tag
2 results in the archive.
Attackers breached Coder's Cloudflare infrastructure to push malicious Terraform modules that embed credential-stealing code, threatening developer credentials.
HashiCorp, Veeam, and the Django Software Foundation released patches for 11 vulnerabilities, including a critical CVSS 10.0 cross-tenant bug affecting Terraform MCP Server, Veeam Service Provider Console, and Django software.