What went wrong
On 31 August 2026, an attacker slipped unauthorized IP addresses into Coder’s module registry pool, which sits behind Cloudflare. Between 07:35 UTC and 21:45 UTC that day, Cloudflare routed a slice of registry traffic to the attacker‑controlled servers, handing out modified Terraform modules to unsuspecting users.
Why it matters
Those modules could run code on the provisioner host. Coder says the payload was designed to harvest environment variables and credentials – a claim that remains unconfirmed.
Technical specifics
The compromised component is the Coder registry at registry.coder.com. The attacker did not gain direct access to the core Coder platform, but by poisoning the supply chain they could influence any Terraform workflow that pulled modules from the registry.
Coder’s own investigation found no evidence that refresh tokens were passed to the provisioner, and no customer‑maintained data appears to have been touched.
To help responders, Coder released an SQL snippet that flags cached modules and template versions that may have been affected:
SELECT module_name, version, cache_timestamp
FROM module_cache
WHERE cache_timestamp BETWEEN '2026-08-31 07:35:00' AND '2026-08-31 21:45:00'
AND source = 'registry.coder.com';Who should be on alert
Any organization using Coder versions 2.37.0, 2.36.4, 2.35.7, or 2.34.9 should assume exposure. The advisory does not list specific customers, but the platform is known to be used by a mix of private firms and government entities.
Immediate defensive steps
- Rotate every secret that could have been used by Terraform provisioners – cloud API keys, CI/CD tokens, SSH keys, OIDC tokens, database passwords.
- Scrutinise firewall, proxy, DNS, and VPC flow logs for outbound connections to
coder‑infra.comduring the attack window. - Search Terraform provisioner logs for the string
data.external.telemetry, which indicates the malicious module was invoked. - Run the SQL query above against your Coder metadata store and treat any returned rows as potentially compromised.
- Consider rebuilding affected infrastructure with fresh credentials and re‑deploying modules from trusted sources.
Unconfirmed claims
Coder alleges the stolen data was exfiltrated to the look‑alike domain coder‑infra.com and that the modules siphoned a long list of secrets, including AI‑tooling API keys and one‑time external authentication tokens. These statements have not been independently verified.