Coder Registry Hijacked to Steal Cloud Secrets
Hackers have hijacked the Coder registry, exposing developers using its Terraform module registry to credential-stealing malware. Unauthorized changes to Coder’s Cloudflare infrastructure allowed threat actors to redirect traffic to attacker-controlled servers. These rogue servers hosted modified Terraform modules designed to extract cloud development credentials. The malicious activity on registry.coder.com persisted between 07:35 UTC and 21:45 UTC on August 31, 2026. Users who created or updated workspaces during this window might have leaked sensitive information, including OIDC tokens and SSH keys.
The malware covertly communicated with coder-infra[.]com, a lookalike domain, to exfiltrate data. Organizations should scrutinize network logs for connections to this domain and check for the presence of specific malicious signatures. Coder insists that customer data remained secure, yet users are urged to update to patched versions and review their deployment records. This coder registry hijacking underscores the vulnerabilities in infrastructure-as-code workflows. To learn more about this incident, visit the official report below.
Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials
