Coder registry served credential-stealing modules
An attacker used a stolen Cloudflare API key to redirect some Coder registry traffic to a malicious server on August 31. The server supplied altered software modules that could send cloud credentials and other secrets to the attacker. Coder stopped the attack that day, but it cannot identify every affected customer deployment.
- Started
- Aug 31, 2026
- Latest activity
- Sep 4, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United States
- Sectors
- Technology
- Scale
- Coder and an unknown number of customer deployments
Current status
No credible incident-specific update was found after Coder's September 4 statement; the registry was clean while customer checks continued.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Impact
Some customers may have installed modules that could send cloud keys, SSH keys, identity tokens, database passwords, and other secrets to the attacker. Coder found no sign that customer data stored by Coder was affected.
What to do
Teams that used the registry during that window should follow Coder's checks, clear affected cached modules, update Coder, and replace credentials the modules could access.
Timeline
-
Sep 4, 2026
Coder said it had fully fixed the registry but advised exposed customers to inspect logs and replace credentials.
Containedcoder.com -
Sep 1, 2026
Coder published an advisory with checks for affected deployments, cleanup steps, and patched versions.
Containedgithub.com -
Aug 31, 2026
By 21:45 UTC, Coder had removed the malicious servers, cleared its cache, and confirmed that the registry was clean.
Containedcoder.com -
Aug 31, 2026
At 07:35 UTC, an attacker began redirecting some registry.coder.com traffic to a server that supplied altered modules.
Activecoder.com
Sources
- Malicious Packages Served from Unauthorized Registry Server GitHub Sep 1, 2026
- Coder Registry Security Incident: What Happened and What to Do Coder Sep 4, 2026
- Coder's registry infrastructure compromised to push malicious modules BleepingComputer Sep 3, 2026
- Coder Registry Compromise: Malicious Terraform Modules Explained eSecurity Planet Sep 4, 2026
- Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules SecurityOnline Sep 5, 2026
- Hackers Hijack Coder Module Registry to Distribute Credential-Stealing Malicious Packages GBHackers Sep 8, 2026
- Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials Cyber Security News Sep 8, 2026