Security.io Intelligence DeskFriday, 4 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Supply Chain · Executive briefing

Coder registry compromise turns module updates into secret-theft investigations

Attacker-controlled registry servers delivered modified Terraform modules that searched developer environments for cloud, CI/CD, AI-tooling, OIDC, SSH and configuration secrets.

Supply ChainIdentityCloud Security
Why it is in today’s brief

The malicious delivery occurred on August 31 and Coder’s advisory appeared September 1; the material change for this edition was September 3 reporting that assembled the registry-pool compromise, secret classes, patched releases and Coder’s inability to conclusively identify every affected deployment. That changes the enterprise decision from normal patching to compromise scoping and coordinated secret rotation, warranting inclusion despite the older initial disclosure.

Read first

Coder disclosed that an unidentified actor added unauthorised servers to infrastructure serving registry.coder.com. Some requests received credential-stealing Terraform modules, requiring local compromise scoping, cache removal and coordinated secret rotation rather than a patch-only response.

Act now

Hunt all network telemetry for coder-infra.com and 199.91.220.205.

Accountable owner

CISO with platform engineering, cloud security, IAM, DevSecOps and incident response

Decision horizon

Hunt and cache scoping immediately; revoke exposed credentials within hours; complete deployment-level disposition within 48 hours.

AssessmentHigh confidence
Emerging riskConfirmed customer exfiltration, additional module variants, an expanded delivery window or evidence that other Coder distribution infrastructure was modified.

What happened

The malicious module-delivery window ran from 07:35 UTC to 21:45 UTC on August 31, 2026. Coder said an unidentified actor gained access to its Cloudflare infrastructure and added unauthorised IP addresses to the pool used for registry.coder.com. Requests were routed to attacker-controlled registry servers that served modified Terraform modules containing credential-stealing code. Coder published GHSA-vx42-ghc9-gw65 on September 1, 2026, and listed versions earlier than 2.37.0 as affected. Coder listed versions earlier than 2.37.0 as affected and identified 2.37.0, 2.36.4, 2.35.7 and 2.34.9 as patched releases.

Potentially exposed material included provisioner environment variables, cloud and AI-tooling API keys, CI/CD credentials, configuration secrets, terminal history, OIDC tokens, SSH keys, one-time external-authentication tokens and, in some architectures, Coder database passwords. The advisory identified coder-infra[.]com, IP address 199.91.220[.]205, URL http://www[.]coder-infra[.]com/cli/check and HTTP header X-CLI-Token: your-secret-token. The published SHA-256 values were 7190a17c593276d7fd71c4863a4bc0b6c957ed14249288e6f64c5540e2c49398 for dlp-docker.sh; a7f4fa5f7e33b2a6f6488cf28444584caa449144d246b083de919162f5514247 for the common dlp.sh; 414d01f6072fbf05bef513e277f4c2b504a413c8e2aa5bae133a5cbc0cda9dc1 for the aider dlp.sh; a64ce3038f2a501c9735abf6a1f9f04cbddbad53371cd68bec0f7510365c8ffa for the rstudio-server dlp.sh; ebbe0d2ed8cfaf9e19edb38ce44d6b407f9771b5c0813a7add27c05f66e89596 for the windows-rdp dlp.sh; and 7ef6b8c3c976fb60b3fa22e9e294ba548d9b532e060c1323a0124a3a7a647f13 for the zed dlp.sh.

On September 3, 2026, BleepingComputer reported that the malicious modules stole credentials and that Coder could not conclusively identify every affected deployment because the malicious infrastructure was outside its control. No CVE was assigned because the central event was a compromise of registry infrastructure rather than a conventional product vulnerability. Attribution posture: Coder identified an unidentified malicious actor and published no named group or sponsor. The cited source did not publish the relevant CVE detail described as The incident has no assigned CVE.

Why this matters now

This was a compromise of a software-distribution trust path, not an ordinary vulnerable package. Requests to a legitimate registry hostname could be routed through unauthorised infrastructure and receive attacker-modified modules. Allow-listing the expected Coder domain or trusting a familiar Terraform source therefore did not establish artefact integrity during the delivery window.

The potential secret exposure spans multiple control planes. Provisioner environments can hold cloud credentials, CI/CD tokens, AI-service keys and configuration secrets, while workspace builds may add user OIDC tokens, SSH keys and one-time external-authentication tokens. Organisations that only update Coder without rotating accessible credentials risk leaving valid post-compromise access in place.

Coder said it could not conclusively determine every affected deployment because communications occurred with malicious infrastructure outside its control. Enterprise closure must therefore be based on local module, cache, job and network evidence. Absence from a vendor-provided victim list cannot serve as proof that a deployment was unaffected.

The decision for security leaders

Declare a potential developer-platform compromise wherever a deployment downloaded modules during the published window. The investigation must join local Coder database evidence, provisioner logs, template versions, workspace builds, network telemetry and credential inventories. A software-version report alone cannot establish whether malicious code executed or secrets left the environment.

Sequence containment by privilege rather than convenience. Revoke cloud-administration, CI/CD, identity, database and AI-service credentials first, then address lower-impact development tokens. Owners should identify dependent automation before rotation, but business-continuity concerns must not leave privileged credentials valid without an explicitly approved exception.

Re-establish artefact trust before new deployments. Purge affected caches, retrieve reviewed modules through validated infrastructure and document the provenance of every restored template. Teams using mirrored registries or internal caches must verify that malicious copies were not preserved beyond the public delivery window.

Evidence of closure

  • SQL results disposition every module and template fetched during the delivery window.
  • Network evidence records whether affected systems contacted coder-infra.com or 199.91.220.205.
  • Cache validation confirms no identified malicious module remains deployable.
  • Credential records prove revocation and replacement of every exposed privileged secret.

The Security.io assessment

The strongest evidence is the vendor’s direct description of unauthorised registry infrastructure and its published indicators. The delivery mechanism means familiar hostnames and normal developer activity could coexist with malicious content, making local execution and egress evidence more important than perimeter allow lists.

Coder’s inability to identify every affected deployment is a material assurance limitation, not an administrative inconvenience. It transfers the final scoping obligation to customers. Organisations without retained DNS, proxy, VPC-flow, provisioner and module-cache evidence may have to rotate a broader credential set because they cannot prove non-exposure.

The central risk is durable credential access after malicious modules are removed. Updating Coder and deleting cached artefacts addresses future execution but does not invalidate secrets already collected. Closure therefore requires separate proof for artefact integrity, execution scope, outbound communication and credential revocation.

Questions for the morning meeting

  • Which Coder deployments downloaded registry modules during the malicious delivery window?
  • Which credentials were accessible to affected provisioners or workspace builds?
  • Can network telemetry prove whether coder-infra.com received outbound connections?
  • Who owns coordinated rotation across cloud, CI/CD, identity and developer platforms?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →