Malicious Terraform modules with credential-stealing code
Malware Activity
Summary
Hide ▲
Show ▼
Malicious Terraform modules were delivered through a compromised registry and ran credential-stealing code, putting developer secrets and cloud credentials at risk. The modules were served during an August 31 delivery window and exfiltrated collected data to coder-infra[.]com. The activity targeted secrets in developer environments and provisioners, including API keys, CI/CD credentials, SSH keys, and OIDC tokens.
Related Happenings
Coder hit by network compromise
Incident
H score38
First: 03.09.2026 23:04
Last: 03.09.2026 23:04
Sources 1
How related:
Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
About this happening:
Coder disclosed an infrastructure compromise of registry.coder.com that let attackers serve malicious Terraform modules to some users and potentially expose secret...
Coder hit by network compromise
IncidentHow related: Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
About this happening: Coder disclosed an infrastructure compromise of registry.coder.com that let attackers serve malicious Terraform modules to some users and potentially expose secret...
Solidity Pro VS Code extension browser wallet and credential stealer
Malware Activity
H score30
First: 10.08.2026 10:38
Last: 10.08.2026 10:38
Sources 1
About this happening:
The Solidity Pro VS Code extension is now flagged as a browser wallet and credential stealer, exposing VS Code users to crypto theft and account compromise. Early vers...
Solidity Pro VS Code extension browser wallet and credential stealer
Malware ActivityAbout this happening: The Solidity Pro VS Code extension is now flagged as a browser wallet and credential stealer, exposing VS Code users to crypto theft and account compromise. Early vers...
TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools
Malware Activity
H score36
First: 30.06.2026 18:34
Last: 30.06.2026 18:34
Sources 1
About this happening:
The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...
TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools
Malware ActivityAbout this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...
CI/CD pull-request privilege-escalation flaw (Cordyceps)
Vulnerability
H score32
First: 24.06.2026 15:48
Last: 24.06.2026 15:48
Sources 1
About this happening:
Cordyceps exposed a CI/CD workflow privilege-escalation flaw in pull-request automation that let unauthenticated users hijack privileged workflows and reach open-s...
CI/CD pull-request privilege-escalation flaw (Cordyceps)
VulnerabilityAbout this happening: Cordyceps exposed a CI/CD workflow privilege-escalation flaw in pull-request automation that let unauthenticated users hijack privileged workflows and reach open-s...
Megalodon GitHub CI/CD supply-chain campaign
Campaign
H score50
First: 22.05.2026 14:55
Last: 22.05.2026 14:55
Sources 1
About this happening:
The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...
Megalodon GitHub CI/CD supply-chain campaign
CampaignAbout this happening: The Megalodon campaign pushed 5,718 malicious commits into 5,561 GitHub repositories in about six hours, creating a broad CI/CD secret-theft risk across develo...
Timeline
-
03.09.2026 23:04 2 articles · 1h ago
Malicious Terraform modules with credential-stealing code
Initial DisclosureUnauthorized registry servers began serving modified Terraform modules during the August 31 delivery window. The modules executed credential-stealing behavior and sent collected secrets to coder-infra[.]com.
Show sources
- Coder's registry infrastructure compromised to push malicious modules — www.bleepingcomputer.com — 03.09.2026 23:04
- Coder's registry infrastructure compromised to push malicious modules — www.bleepingcomputer.com — 03.09.2026 23:04