CTIPilot
← Back to Daily brief 2026-09-04
HIGHNATOA2incident

Coder's Cloudflare-fronted Terraform module registry was compromised for 14 hours, serving trojanized modules that harvested cloud, CI/CD and AI-tooling credentials

An attacker who never touched Coder's source code hijacked its CDN routing to serve credential-stealing Terraform modules for half a day

Defender actions

  • For any Coder deployment that created or updated a workspace template, ran a template-build dry run, or built a workspace without module caching disabled (module caching is on by default) between 2026-08-31 07:35 and 21:45 UTC: rotate every credential a provisioner job in that window could have accessed, cloud/AI-tooling API keys, CI/CD credentials, OIDC tokens, configured SSH keys, and, where the provisioner ran inside coderd itself, the Coder deployment's own database password.

Analysis

Coder (a self-hosted cloud-development-environment platform whose customers include, per BleepingComputer, Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, and US government agencies and defense contractors) disclosed that an unidentified actor gained access to the Cloudflare infrastructure fronting registry.coder.com, its Terraform-module package registry, and added unauthorized origin IP addresses to the CDN's server pool (Coder, GitHub Security Advisory GHSA-vx42-ghc9-gw65, 2026-09-01). For roughly 14 hours on 2026-08-31 (07:35-21:45 UTC), Cloudflare routed a subset of registry requests to the attacker's servers instead of Coder's own, serving modified Terraform modules containing credential-stealing code. The malicious modules searched for and exfiltrated provisioner environment variables and secrets, cloud-infrastructure and AI-tooling API keys, CI/CD credentials, configuration-file secrets, terminal history, user OIDC tokens, configured SSH keys, one-time external-auth tokens, and (when the provisioner ran inside coderd itself) the Coder deployment's own database password and other configuration secrets, sent to a lookalike domain registered 2026-08-28 that impersonates Coder's own infrastructure naming convention.

Exposure requires only that a deployment created or updated a workspace template, ran a template-build dry run, or built a workspace without module caching during the exposure window; module caching is on by default, so a deployment relying on the default configuration was still exposed on any fresh template build. Coder states it "does not have access to crucial logs and cannot conclusively identify every compromised deployment," because the credential-theft traffic went to infrastructure entirely outside its own control (BleepingComputer, reporting Coder's advisory, 2026-09-03). No refresh tokens were exposed, and Coder reports no evidence of impact to data it directly maintains. Fixed in 2.37.0, 2.36.4, 2.35.7 and 2.34.9, released 2026-09-01; the currently-served registry content has been reviewed and confirmed clean.

Cited evidence

An unidentified malicious actor gained access to Coder's Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder's module registry. These unauthorized IP addresses hosted a version of Coder's registry that contained artifacts which included malicious code.

Coder (GitHub Security Advisory) 2026-09-01

the delivery window for the malicious artifacts was between 07:35 UTC and 21:45 UTC on Monday, August 31

Coder / BleepingComputer

because the attacker's infrastructure is outside the project's control, Coder does not have access to crucial logs and cannot conclusively identify every compromised deployment

BleepingComputer, reporting Coder's advisory

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.