Coder: Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials

Coder: Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials

Critical Supply-Chain Attack on Coder’s Terraform Registry Exposes Cloud Credentials

On August 31, 2026, Coder a provider of cloud development environments disclosed a security breach in its Terraform module registry, where attackers hijacked infrastructure to distribute malicious packages designed to steal credentials. The incident stemmed from unauthorized modifications to Coder’s Cloudflare configuration, allowing threat actors to redirect traffic from registry.coder.com to attacker-controlled servers between 07:35 UTC and 21:45 UTC.

The rogue registry hosted tampered Terraform modules containing credential-stealing malware. The attack targeted organizations using Coder workspace templates, particularly those performing template imports, updates, dry runs, or workspace deployments with Terraform module caching disabled. The malicious code, embedded in a data.external.telemetry block, executed a script (dlp-docker.sh) that exfiltrated secrets including environment variables, OIDC tokens, SSH keys, and temporary authentication credentials to a lookalike domain, coder-infra[.]com (resolving to 199.91.220[.]205).

The impact varied by deployment model. In standard provisioner environments, the malware accessed local secrets, while deployments running the provisioner within Coder’s main service risked exposure of database credentials, external authentication provider settings, and other application secrets. Coder confirmed no evidence of direct compromise to its customer data storage.

To mitigate the threat, Coder released patched versions (2.37.0, 2.36.4, 2.35.7, 2.34.9) and advised users to:

  • Remove cached modules downloaded during the attack window.
  • Update to the latest secure versions.
  • Audit logs for connections to coder-infra[.]com or the data.external.telemetry string.
  • Rotate all potentially exposed credentials, including cloud API keys, CI/CD secrets, and SSH keys.

The incident underscores the growing risk of supply-chain attacks in infrastructure-as-code workflows, where compromised registries can serve as vectors for credential theft. Security teams are urged to scrutinize trusted sources for similar threats.

Source: https://cybersecuritynews.com/hackers-hijack-coder-registry/

Coder cybersecurity rating report: https://www.rankiteo.com/company/coder

"id": "COD1788855826",
"linkid": "coder",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Organizations using Coder '
                                              'workspace templates with '
                                              'Terraform module caching '
                                              'disabled',
                        'industry': 'Cloud Development Environments',
                        'name': 'Coder',
                        'type': 'Company'}],
 'attack_vector': 'Compromised Terraform Registry',
 'customer_advisories': 'Advisory to remove cached modules, update to patched '
                        'versions, rotate credentials, and audit logs',
 'data_breach': {'data_exfiltration': 'Exfiltrated to *coder-infra[.]com* '
                                      '(199.91.220[.]205)',
                 'personally_identifiable_information': 'OIDC tokens, SSH '
                                                        'keys, environment '
                                                        'variables',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Credentials, authentication '
                                             'tokens, SSH keys, database '
                                             'credentials, cloud API keys, '
                                             'CI/CD secrets'},
 'date_detected': '2026-08-31T21:45:00Z',
 'date_publicly_disclosed': '2026-08-31',
 'description': 'On August 31, 2026, Coder disclosed a security breach in its '
                'Terraform module registry, where attackers hijacked '
                'infrastructure to distribute malicious packages designed to '
                'steal credentials. The incident stemmed from unauthorized '
                'modifications to Coder’s Cloudflare configuration, allowing '
                'threat actors to redirect traffic from *registry.coder.com* '
                'to attacker-controlled servers between 07:35 UTC and 21:45 '
                'UTC. The rogue registry hosted tampered Terraform modules '
                'containing credential-stealing malware targeting '
                'organizations using Coder workspace templates.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': 'Environment variables, OIDC tokens, SSH keys, '
                                'temporary authentication credentials, '
                                'database credentials, external authentication '
                                'provider settings, cloud API keys, CI/CD '
                                'secrets',
            'identity_theft_risk': 'High',
            'operational_impact': 'Potential exposure of sensitive '
                                  'credentials, required credential rotation '
                                  'and module updates',
            'systems_affected': 'Terraform module registry, Coder workspace '
                                'templates, provisioner environments'},
 'initial_access_broker': {'backdoors_established': 'Redirect traffic to '
                                                    'attacker-controlled '
                                                    'servers',
                           'entry_point': 'Unauthorized Cloudflare '
                                          'configuration modifications',
                           'high_value_targets': 'Organizations using Coder '
                                                 'workspace templates with '
                                                 'Terraform module caching '
                                                 'disabled'},
 'lessons_learned': 'Growing risk of supply-chain attacks in '
                    'infrastructure-as-code workflows, need to scrutinize '
                    'trusted sources for similar threats',
 'motivation': 'Credential Theft',
 'post_incident_analysis': {'corrective_actions': 'Patch releases, credential '
                                                  'rotation, log audits, '
                                                  'enhanced scrutiny of '
                                                  'trusted sources',
                            'root_causes': 'Unauthorized modifications to '
                                           'Cloudflare configuration, lack of '
                                           'Terraform module caching'},
 'recommendations': 'Remove cached modules from attack window, update to '
                    'latest secure versions, audit logs for malicious '
                    'activity, rotate all potentially exposed credentials',
 'references': [{'source': 'Coder Public Disclosure'}],
 'response': {'communication_strategy': 'Public disclosure and advisory to '
                                        'users',
              'containment_measures': 'Released patched versions (2.37.0, '
                                      '2.36.4, 2.35.7, 2.34.9), advised '
                                      'removal of cached modules downloaded '
                                      'during the attack window',
              'recovery_measures': 'Audit logs for connections to '
                                   '*coder-infra[.]com* or '
                                   '*data.external.telemetry* string',
              'remediation_measures': 'Updated to latest secure versions, '
                                      'rotated all potentially exposed '
                                      'credentials'},
 'title': 'Critical Supply-Chain Attack on Coder’s Terraform Registry Exposes '
          'Cloud Credentials',
 'type': 'Supply-Chain Attack',
 'vulnerability_exploited': 'Unauthorized Cloudflare configuration '
                            'modifications, Terraform module caching disabled'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.