Coder's trusted module registry served credential-stealing Terraform modules after a Cloudflare API-key compromise.
Fetching a module during the exposure window was enough to run attacker code in the provisioner context.
Coder, self-hosted cloud-development-environment infrastructure whose Terraform modules execute in workspace provisioners
Execution of attacker-supplied Terraform modules in trusted Coder provisioning workflows and theft of provisioner, cloud, CI, SSH, OIDC and database credentials
This was an actual replacement of trusted provisioning artifacts, and correcting the registry origin did not remove cached modules or complete credential revocation.
Detail, proof-of-concept code and 3 sources
The compromised key added attacker-controlled origin IPs to registry.coder.com. When Cloudflare routed a module request there, Terraform invoked an external-data script that searched the provisioner environment and configuration for cloud, CI, SSH, OIDC and database credentials.
Previously fetched modules can remain in caches, and credential revocation was incomplete at publication. Coder supplied malicious hashes, an invocation marker and detection queries for finding affected artifacts.
- Pre-fix images still accepted
- Yes
- Revocation complete
- No
- Reaches end-of-life hardware
- No
The purge-window lower bound is 25 minutes later than the incident start published in the advisory.