CTIPilot

Coder

product · product:coder single-source-victim

Coverage timeline
1
first 2026-09-04 → last 2026-09-04
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
2
see Co-occurring entities below
ATT&CK techniques
3
pinned v19.2 · see below

Hunting pivots

Releases covered
Coder

ATT&CK techniques

3 techniques observed across 1 entry, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1195.002Supply Chain Compromise: Compromise Software Supply Chain×1

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of software can take place in a number of ways, including manipulation of the application source code, manipulation of the update/distribution mechanism for that software, or replacing compiled releases with a modified version.

Evidence: 2026-09-04/coder-terraform-registry-cloudflare-compromise · ATT&CK page ↗

Credential Access TA0006

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-09-04/coder-terraform-registry-cloudflare-compromise · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-09-04/coder-terraform-registry-cloudflare-compromise · ATT&CK page ↗

Story timeline

  1. 2026-09-04Coder's Cloudflare-fronted Terraform module registry was compromised for 14 hours, serving trojanized modules that harvested cloud, CI/CD and AI-tooling credentials
    active-threatsAn attacker who never touched Coder's source code hijacked its CDN routing to serve credential-stealing Terraform modules for half a day

Where this entity is cited

  • active-threats1

Source distribution

  • bleepingcomputer.com1 (50%)
  • github.com1 (50%)

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Coder (1)

2026-09-04 · view entry permalink →

HIGHNATOA2

Coder's Cloudflare-fronted Terraform module registry was compromised for 14 hours, serving trojanized modules that harvested cloud, CI/CD and AI-tooling credentials

Coder (a self-hosted cloud-development-environment platform whose customers include, per BleepingComputer, Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, and US government agencies and defense contractors) disclosed that an unidentified actor gained access to the Cloudflare infrastructure fronting registry.coder.com, its Terraform-module package registry, and added unauthorized origin IP addresses to the CDN's server pool (Coder, GitHub Security Advisory GHSA-vx42-ghc9-gw65, 2026-09-01). For roughly 14 hours on 2026-08-31 (07:35-21:45 UTC), Cloudflare routed a subset of registry requests to the attacker's servers instead of Coder's own, serving modified Terraform modules containing credential-stealing code. The malicious modules searched for and exfiltrated provisioner environment variables and secrets, cloud-infrastructure and AI-tooling API keys, CI/CD credentials, configuration-file secrets, terminal history, user OIDC tokens, configured SSH keys, one-time external-auth tokens, and (when the provisioner ran inside coderd itself) the Coder deployment's own database password and other configuration secrets, sent to a lookalike domain registered 2026-08-28 that impersonates Coder's own infrastructure naming convention.

Exposure requires only that a deployment created or updated a workspace template, ran a template-build dry run, or built a workspace without module caching during the exposure window; module caching is on by default, so a deployment relying on the default configuration was still exposed on any fresh template build. Coder states it "does not have access to crucial logs and cannot conclusively identify every compromised deployment," because the credential-theft traffic went to infrastructure entirely outside its own control (BleepingComputer, reporting Coder's advisory, 2026-09-03). No refresh tokens were exposed, and Coder reports no evidence of impact to data it directly maintains. Fixed in 2.37.0, 2.36.4, 2.35.7 and 2.34.9, released 2026-09-01; the currently-served registry content has been reviewed and confirmed clean.

An unidentified malicious actor gained access to Coder's Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder's module registry. These unauthorized IP addresses hosted a version of Coder's registry that contained artifacts which included malicious code.

Coder (GitHub Security Advisory) 2026-09-01

the delivery window for the malicious artifacts was between 07:35 UTC and 21:45 UTC on Monday, August 31

Coder / BleepingComputer

because the attacker's infrastructure is outside the project's control, Coder does not have access to crucial logs and cannot conclusively identify every compromised deployment

BleepingComputer, reporting Coder's advisory
incident04 Sep 06:00Zsingle-source · victim disclosureOpen finding ↗