Security1 distinct publisher2 min readPublished
Coder says an unidentified actor reached its Cloudflare infrastructure and pointed part of registry.coder.com at servers it controlled. Because those servers are unreachable, nobody can enumerate who downloaded what.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Origin pool membership is a write operation on the CDN account, not on the origin host. Per Coder's advisory, the actor added unauthorized IP addresses to the pool Cloudflare uses for the module registry [1]. The substitution happened at the layer that decides which origin answers, so from the client side the hostname and the TLS front end were the same ones the build used yesterday, with no server compromise and no forged certificate involved [19]. Cloudflare then routed some registry requests to the attacker's servers and delivered malicious files to a subset of users [2].
The window Coder gives is 07:35 UTC to 21:45 UTC on Monday, August 31 [4]. That is 14 hours 10 minutes, or 850 minutes of build traffic [5]. Terraform modules are prepackaged instructions for creating and configuring infrastructure [20], so what matters for any one deployment is how many workspace builds and provisioner runs landed inside that band, not how many developers are on the roster.
The stealer swept eight classes of secret [7]: provisioner environment variables, cloud and AI-tooling API keys, CI/CD credentials, configuration-file secrets and terminal history, user OIDC tokens, SSH keys, one-time external authentication tokens, and, when the provisioner ran inside coderd, Coder database passwords and other configuration secrets [6]. That last condition is the one to check first. It moves the loss from a workspace's credentials to the platform's own. Collected data went to the lookalike domain coder-infra[.]com [8]. Coder says refresh tokens were never passed to the provisioner and that it has no evidence of impact to customer data it holds [15].
The evidentiary problem is harder than the technical one. The attacker's infrastructure sits outside Coder's control, so Coder has no access to the delivery logs and cannot conclusively identify every compromised deployment [16]. Verification is therefore local work: egress records from firewall, proxy, DNS and VPC flow logs checked for coder-infra[.]com [12], provisioner logs searched for data.external.telemetry with the downloaded modules identified and cached packages purged [13], and the SQL query Coder published run against cached modules and template versions [14]. A clean result only means something if the retention covers August 31.
Fixes shipped across four release branches, 2.37.0, 2.36.4, 2.35.7 and 2.34.9 [10][11]. What those releases actually change is unspecified, and upgrading a version does not undo a stolen key; Coder's own instruction is to rotate everything on the list [9]. Coder's self-hosted development environments are run by Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government and defense contractors [17][18], each of which has to do that rotation itself.
Ranked by verification strength, evidence, and original report placement.
Coder's advisory states: "An unidentified malicious actor gained access to Coder's Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder's module registry," and that those IP addresses hosted a version of Coder's registry containing artifacts with malicious code.
Coder's registry runs behind Cloudflare; the attacker accessed the underlying infrastructure and added unauthorized servers to the registry's pool, so Cloudflare routed some registry requests to the attacker's servers instead of Coder's, delivering malicious files to a subset of users.
Earlier this week Coder disclosed that an attacker targeted registry.coder.com, the project's package-hosting site that developers use to source components for their workspace templates.
Coder said the delivery window for the malicious artifacts was between 07:35 UTC and 21:45 UTC on Monday, August 31, during which the malicious servers delivered modified versions of Terraform modules.
Coder said the malicious modules acted as information stealers, searching for provisioner environment variables and secrets; cloud infrastructure and AI-tooling API keys; CI/CD credentials; configuration-file secrets and terminal history; user OIDC tokens; configured SSH keys; one-time external authentication tokens; and Coder database passwords and other configuration secrets when the provisioner ran within coderd.
The collected information was exfiltrated to the lookalike domain coder-infra[.]com.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
77 linked Firefox add-ons, one pipeline: store review is a checkpoint, not a control1 distinct publisher
product
Pulumi points a security agent at its context graph to hunt cloud attack paths1 distinct publisher
build
Shai-Hulud spreads by bumping a version number your dependency range already accepts2 distinct publishers
build
Fabricated SQLite CVEs cleared NVD, CISA ADP and Red Hat before anyone ran the code1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific, checkable, single-sourced
Every fact of consequence — the 07:35 to 21:45 UTC window, the eight secret classes, the exfiltration domain, the four patched branches — traces back to Coder's own advisory as relayed by BleepingComputer. It is unusually operational for a breach note, and the published SQL query and log search string mean a reader can test their own exposure rather than take the vendor's word. What is missing is anything from outside: no Cloudflare statement, no researcher who captured the modified module, no second newsroom checking the timeline.
Big install base, uncountable blast radius
There is real footprint behind this: named users spanning Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW and US government and defense buyers, plus fixes on four live release lines, which is what a widely deployed and actively maintained product looks like. The number that would define the incident, though, does not exist anywhere in this reporting — how many deployments actually fetched a poisoned module. The attacker's servers are gone and Coder says the logs that would answer it were never in its hands.
Reads flatter than it is
The prose is dry and stops exactly where the advisory stops: timestamps, one indicator, a rotate-these list. Set that against what was reportedly taken — cloud and AI API keys, CI/CD credentials, SSH keys, OIDC tokens, and in some configurations Coder's own database passwords, from provisioners at defense and government users — and the restraint sits a notch below the stakes rather than above them. No claim here outruns its evidence; the headline finding, that nobody can enumerate the victims, is the vendor's own conclusion.
Self-report, with a sponsor at the foot
Two pulls are worth naming. The scope-limiting lines — refresh tokens never reached the provisioner, no evidence of impact to maintained customer data — come from the party whose registry was hijacked, and they are exactly the reassurances a vendor most wants on the record while forensic visibility is absent. Separately, BleepingComputer's piece closes with a pitch for a commercial breach-simulation report unrelated to Coder: the ordinary economics of security publishing, worth flagging so a reader knows where the reporting ends and the marketing begins.
Coherent account, unverifiable by construction
We would rate this higher if anyone else could check it. The mechanism hangs together, the remediation steps are concrete enough to execute today, and the vendor is candid about what it does not know. But the same candour is the ceiling: with the attacker's origins outside Coder's reach, the records that would settle who downloaded what were never collected, and a single newsroom relaying a single advisory leaves no second reading to test it against.