TechNewsReel
Live

Coder Registry Breach Leaks Cloud Secrets via Malicious Terraform Modules

Attackers manipulated Cloudflare infrastructure to serve credential-stealing code to developers using Coder's module registry.

TechNewsReel Newsroom · September 3, 2026

Attackers compromised Coder's Cloudflare infrastructure to inject malicious Terraform modules into the company's registry, stealing high-value credentials from a subset of users. The breach represents a targeted supply chain attack on infrastructure-as-code components used to provision cloud development environments.

According to a security advisory from Coder, the attack occurred on Monday, August 31, 2026, between 07:35 UTC and 21:45 UTC. During this window, an unidentified actor gained access to Coder’s Cloudflare configuration and added unauthorized IP addresses to the server pool for registry.coder.com. These rogue servers delivered modified Terraform modules containing malicious code designed to exfiltrate sensitive data, including API keys, CI/CD credentials, and OIDC tokens. The stolen data was sent to a lookalike domain, coder-infra.com, which records show was registered on August 28, 2026.

The Infrastructure Target

Coder provides secure, self-hosted cloud development environments for a client base that includes high-profile organizations such as Dropbox, Palantir, Square, and Mercedes-Benz, as well as various U.S. government and defense agencies. Developers rely on the registry.coder.com site to source the essential components used in their workspace templates. By compromising the delivery mechanism rather than the source code itself, the attackers were able to intercept requests and serve poisoned modules to users without altering the official codebase.

Industry Implications

This incident highlights a critical vulnerability in the infrastructure-as-code supply chain. Because the malicious servers operated outside of Coder's direct control, the company cannot conclusively identify every compromised deployment. This forces affected organizations to perform manual audits of their logs and rotate all potentially exposed secrets. The theft of OIDC tokens and cloud API keys is particularly severe, as these credentials often grant broad administrative access to cloud environments, potentially allowing attackers to move laterally within a victim's infrastructure.

Next Steps for Users

Coder has since remediated the unauthorized access to its Cloudflare infrastructure. However, the company advises all users who accessed the registry during the August 31 window to treat their secrets as compromised. Organizations are urged to rotate all API keys and tokens that may have been active during the attack. Security teams should monitor for any unauthorized activity originating from the coder-infra.com domain or unexpected changes in their cloud environment configurations.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.