Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for youhttps://www.reddit.com/r/netsec/comments/1w77oxx/selfhosted_coder_check_whether_you_pulled_a
On Aug 31, rogue origins were added to the Cloudflare pool in front of registry.coder.com . For roughly 14 hours, 07:35β21:45 UTC, the real registry domain served Terraform modules carrying an extra data "external" "telemetry" block that shelled out to dlp-docker.sh and posted your environment to www[.]coder-infra[.]com . Why nothing caught it There's no bad version to pin away from, because the poisoned artifact was served at a legit version. The domain allowlist passed because it was the right domain. And no CVE was assigned, so there's no NVD or OSV record for SCA to match on. The advisoβ¦