Affected Systems
Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected. Patched versions: 2.37.0, 2.36.4, 2.35.7, and 2.34.9. Organizations using Coder for cloud development environments at risk, including government and enterprise deployments.
Exploitation Status
Active supply chain attack confirmed. Malicious infrastructure delivered credential-stealing Terraform modules to subset of Coder registry users during 14-hour window on August 31, 2026. Attacker-controlled domain coder-infra[.]com used for exfiltration. Full scope unknown due to lack of access to attacker logs.
Business Impact
High-value credentials at risk including cloud API keys, CI/CD credentials, SSH keys, OIDC tokens, and database passwords. Developers using Coder registry during exposure window may have deployed malicious infrastructure-as-code modules into production environments. Attacker gained access to provisioner secrets and environment variables. Organizations cannot definitively confirm compromise status without log analysis. Potential lateral movement risk if stolen credentials remain valid.
Urgency
🔴 Immediate
Recommended Actions
- Immediately rotate all provisioner secrets, cloud API keys, CI/CD credentials, SSH keys, OIDC tokens, and database passwords for any Coder deployment active on August 31, 2026
- Search firewall, proxy, DNS, and VPC flow logs for connections to coder-infra[.]com domain to identify compromised systems
- Query provisioner logs for 'data.external.telemetry' string and identify all Terraform modules downloaded between 07:35-21:45 UTC on August 31, 2026
- Upgrade Coder installations to patched versions: 2.37.0, 2.36.4, 2.35.7, or 2.34.9 depending on release track
- Purge cached Terraform module packages downloaded during exposure window and run Coder-provided SQL query to identify affected template versions
