Contained Medium impact Supply chain Checked 12h ago

Coder registry served credential-stealing modules

An attacker used a stolen Cloudflare API key to redirect some Coder registry traffic to a malicious server on August 31. The server supplied altered software modules that could send cloud credentials and other secrets to the attacker. Coder stopped the attack that day, but it cannot identify every affected customer deployment.

Started
Aug 31, 2026
Latest activity
Sep 4, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States
Sectors
Technology
Scale
Coder and an unknown number of customer deployments

Current status

No credible incident-specific update was found after Coder's September 4 statement; the registry was clean while customer checks continued.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Impact

Some customers may have installed modules that could send cloud keys, SSH keys, identity tokens, database passwords, and other secrets to the attacker. Coder found no sign that customer data stored by Coder was affected.

What to do

Teams that used the registry during that window should follow Coder's checks, clear affected cached modules, update Coder, and replace credentials the modules could access.

Timeline

  1. Sep 4, 2026

    Coder said it had fully fixed the registry but advised exposed customers to inspect logs and replace credentials.

    Containedcoder.com
  2. Sep 1, 2026

    Coder published an advisory with checks for affected deployments, cleanup steps, and patched versions.

    Containedgithub.com
  3. Aug 31, 2026

    By 21:45 UTC, Coder had removed the malicious servers, cleared its cache, and confirmed that the registry was clean.

    Containedcoder.com
  4. Aug 31, 2026

    At 07:35 UTC, an attacker began redirecting some registry.coder.com traffic to a server that supplied altered modules.

    Activecoder.com

Sources

Related reports