Coder Registry Compromise: Malicious Terraform Modules Explained
This story is from 2026-09-05. It is preserved in the archive; the latest stories are on the live feed.
Coder's module registry was compromised last month. Attackers had a 14-hour window to serve poisoned Terraform modules to every team pulling from it. The payload targeted AI credentials specifically — the tokens agents use to authenticate to models, data pipelines, and infrastructure stores. Any or…
Read the full story at r/deeplearning ↗
Timeline · 1 report
- 2026-09-05 22:51 · r/deeplearning
Coder Registry Compromise: Malicious Terraform Modules Explained