Coder Registry Distributed Malicious Terraform Modules After Infrastructure Compromise

The compromise of Coder Registry infrastructure on August 31, 2026, led to the delivery of Terraform modules containing credential-targeting malicious code.

The compromise of Coder Registry allowed Terraform modules containing embedded malicious code to be distributed during a time-limited incident. According to a security notice from Coder cited by BleepingComputer, the issue involved unauthorized IP addresses in the pool for registry.coder.com. Malicious artifacts may have been delivered from August 31, 2026, at 07:35 through 21:45 UTC.

Coder Registry is used to publish and download reusable Terraform modules for Coder workspaces. The incident therefore falls among supply chain attacks: instead of directly attacking a specific environment, an attacker can insert malicious code into a component that development and operations teams automatically download when provisioning infrastructure.

Coder Registry compromise redirected requests

During the incident, some requests to registry.coder.com were routed to unauthorized servers. Those servers provided Terraform modules containing malicious code. Its targets were secrets and credentials available to the provisioner—the process that creates or configures a workspace and related infrastructure.

According to the available information, the malicious code was supposed to send obtained data to the coder-infra[.]com domain. This potentially included cloud access credentials, CI/CD system credentials, SSH keys, OIDC data and other secrets accessible to the provisioner in a particular deployment.

The delivery of malicious artifacts has been confirmed, but not the extent of their use. The number of affected deployments and how many credentials may have been stolen are unknown. Active exploitation of potentially obtained data has likewise not been confirmed.

Fixes and recommended steps for administrators

Coder released the fixed versions 2.37.0, 2.36.4, 2.35.7 and 2.34.9. Organizations should review the versions they use and follow Coder’s guidance on the fixed versions. They should also review their logs for the incident period.

  • check logs for module downloads and use between August 31, 07:35 and 21:45 UTC,
  • remove suspicious cached modules,
  • rotate secrets and credentials that may have been available to the provisioner,
  • pay attention to communications directed to the coder-infra[.]com domain.

The scope of the review should be based on the permissions provisioning processes had in the given environment. In automated deployments, such processes may have access to sensitive data needed to create cloud resources, configure workspaces or integrate with internal systems.

Incident scope remains unclear

Coder said it does not have access to the attacker’s critical infrastructure logs. The company therefore cannot definitively identify all compromised installations. It has also not been independently confirmed who carried out the attack or how access to the Cloudflare configuration was obtained.

The company also said that customer data managed by Coder was not affected. However, this is the company’s statement, not an independent forensic conclusion. Further information may come from any security advisories containing indicators of compromise, artifact hashes and a complete list of affected modules, as well as a statement from Cloudflare regarding the unauthorized IP addresses.

Sources

  • BleepingComputer – Reports the incident time window, the redirection of requests to unauthorized servers, the coder-infra[.]com indicator and the recommended fixed versions.
  • coder/registry on GitHub – Confirms Coder Registry’s role as a platform for publishing and using Terraform modules and the significance of a potential compromise of the distribution channel.

Verified and updated: 09/04/2026 06:25

Sharing