Find notable cyber news and cases, enriched with sources, timelines, and signals.

Malicious Terraform modules with credential-stealing code

Malware Activity
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

Malicious Terraform modules were delivered through a compromised registry and ran credential-stealing code, putting developer secrets and cloud credentials at risk. The modules were served during an August 31 delivery window and exfiltrated collected data to coder-infra[.]com. The activity targeted secrets in developer environments and provisioners, including API keys, CI/CD credentials, SSH keys, and OIDC tokens.

Related Happenings

Coder hit by network compromise

Incident
H score38 First: 03.09.2026 23:04 Last: 03.09.2026 23:04 Sources 1

How related: Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.

About this happening: Coder disclosed an infrastructure compromise of registry.coder.com that let attackers serve malicious Terraform modules to some users and potentially expose secret...

Solidity Pro VS Code extension browser wallet and credential stealer

Malware Activity
H score30 First: 10.08.2026 10:38 Last: 10.08.2026 10:38 Sources 1

About this happening: The Solidity Pro VS Code extension is now flagged as a browser wallet and credential stealer, exposing VS Code users to crypto theft and account compromise. Early vers...

TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools

Malware Activity
H score36 First: 30.06.2026 18:34 Last: 30.06.2026 18:34 Sources 1

About this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...

CI/CD pull-request privilege-escalation flaw (Cordyceps)

Vulnerability
H score32 First: 24.06.2026 15:48 Last: 24.06.2026 15:48 Sources 1

About this happening: Cordyceps exposed a CI/CD workflow privilege-escalation flaw in pull-request automation that let unauthenticated users hijack privileged workflows and reach open-s...

Megalodon GitHub CI/CD supply-chain campaign

Campaign
H score50 First: 22.05.2026 14:55 Last: 22.05.2026 14:55 Sources 1

About this happening: The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...

Timeline

  1. 03.09.2026 23:04 2 articles · 1h ago

    Malicious Terraform modules with credential-stealing code

    Initial Disclosure

    Unauthorized registry servers began serving modified Terraform modules during the August 31 delivery window. The modules executed credential-stealing behavior and sent collected secrets to coder-infra[.]com.

    Show sources