Malicious Terraform modules served from Coder’s compromised Cloudflare infrastructure
On August 31, 2026, between 07:35 and 21:45 UTC, an attacker compromised a Coder Cloudflare API key and redirected part of the module registry’s traffic to a malicious server that exfiltrated cloud credentials. Check your logs for coder-infra[.]com and rotate the affected secrets.