Coder Cloud Infrastructure Compromised to Distribute Malicious Terraform Module
Attackers compromised Coder’s Cloudflare infrastructure and added an unauthorized registry server that distributed a malicious Terraform module containing credential-stealing code.
Coder provides organizations with a secure, self-hosted cloud development environment for building and deploying software, including artificial intelligence applications.
The platform is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government, and defense companies.
Earlier this week, Coder disclosed that registry.coder.com, a package-hosting service developers use to source components for workspace templates, had been targeted by attackers.
Coder’s registry operates behind Cloudflare. However, the attackers gained access to the underlying infrastructure and added unauthorized servers to the registry’s server pool.
Cloudflare subsequently routed some registry requests to the attackers’ servers instead of Coder’s legitimate infrastructure. As a result, some users downloaded malicious files.
“An unknown malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry,” Coder said in a security advisory.
“These unauthorized IP addresses were hosting versions of Coder’s registry that contained artifacts containing malicious code.”
According to Coder, the malicious artifact was distributed between 07:35 UTC and 21:45 UTC on Monday, August 31.
During that period, the malicious server distributed a modified Terraform module—a collection of reusable instructions for creating and configuring cloud and computing infrastructure.
Coder said the malicious module attempted to steal sensitive information from infected hosts, including:
- Provisioner environment variables and secrets
- Cloud infrastructure and AI tool API keys
- CI/CD credentials
- Secrets stored in configuration files and device history
- User OIDC tokens
- Configured SSH keys
- One-time external authentication tokens
- Coder database passwords and other configuration secrets when the provisioner runs within
coderd
The stolen information was exfiltrated to the domain coder-infra[.]com.
Potentially affected users should rotate all potentially exposed credentials and secrets as soon as possible.
Before upgrading to the patched Coder releases 2.37.0, 2.36.4, 2.35.7, or 2.34.9, the company recommends reviewing firewall, proxy, DNS, and VPC flow logs for connections to coder-infra[.]com.
Developers should also search provisioner logs for data.external.telemetry to identify modules downloaded during the affected period and remove potentially malicious packages from local caches.
To help customers determine whether they were affected, Coder shared a SQL query that can identify cached module and template versions downloaded during the affected window.
Coder said refresh tokens were not passed to provisioners and that there was no evidence that customer data stored by provisioners had been accessed.
However, because the attackers’ infrastructure was outside Coder’s control, the company does not have access to all relevant logs and cannot conclusively determine whether every deployment was compromised.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop dramatically.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



