Close Menu
NCIJ Network NCIJ Network
    What's Hot

    JD Vance Says He Wouldn’t Call Iran Conflict a War

    September 3, 2026

    Startup ARR is less secure than ever, new research shows

    September 3, 2026

    Playco cut manual fixes 50% prototyping games with GPT-6 Astra

    September 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • JD Vance Says He Wouldn’t Call Iran Conflict a War
    • Startup ARR is less secure than ever, new research shows
    • Playco cut manual fixes 50% prototyping games with GPT-6 Astra
    • Coder’s registry infrastructure compromised to push malicious modules
    • Michigan Authorities Continue Pursuit to Block Kalshi as Supreme Court Fight Looms
    • AI agents not ready to replace humans in behavioral research
    • Ebola outbreak underscores food insecurity crisis in DRC
    • AI-powered digital twin to be developed for wave energy technology
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Coder’s registry infrastructure compromised to push malicious modules

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.

    The Coder platform enables organizations to provide developers with secure, self-hosted cloud development environments for building and deploying software, including AI applications.

    The project is used by prominent private and government organizations, including Dropbox, Palantir, Square, Mercedes-Benz, KKR, EnBW, the U.S. government, and defense companies.

    Earlier this week, Coder disclosed that an attacker targeted registry.coder.com, the project’s package-hosting site that developers use to source components for their workspace templates.

    Although Coder’s registry runs behind Cloudflare, the attacker accessed its underlying infrastructure and added unauthorized servers to the registry’s pool.

    As a result, Cloudflare routed some registry requests to the attacker’s servers, instead of Coder’s legitimate servers, delivering malicious files to a subset of users.

    “An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry,” reads Coder’s advisory.

    “These unauthorized IP addresses hosted a version of Coder’s registry that contained artifacts which included malicious code.”

    The project said that the delivery window for the malicious artifacts was between 07:35 UTC and 21:45 UTC on Monday, August 31.

    During this time, the malicious servers delivered modified versions of Terraform modules, which are ready-made bundles of instructions for creating and configuring computing infrastructure.

    According to Coder, the malicious modules acted as information stealers on infected hosts, searching for:

    • Provisioner environment variables and secrets
    • Cloud infrastructure and AI-tooling API keys
    • CI/CD credentials
    • Configuration-file secrets and terminal history
    • User OIDC tokens
    • Configured SSH keys
    • One-time external authentication tokens
    • Coder database passwords and other configuration secrets when the provisioner ran within ‘coderd’

    The collected information was exfiltrated to the lookalike domain ‘coder-infra[.]com.’

    It is recommended that potentially impacted users rotate all impacted secrets mentioned in the above list as soon as possible.

    Before upgrading to a patched release, versions 2.37.0, 2.36.4, 2.35.7, and 2.34.9, Coder recommends that users examine firewall, proxy, DNS, and VPC flow logs for connections to coder-infra[.]com.

    Developers should also search provisioner logs for data.external.telemetry, identify modules downloaded during the exposure window, and purge potentially malicious cached packages.

    To help users determine if they were impacted, Coder shared an SQL query that can identify potentially affected cached modules and template versions.

    The project said refresh tokens were not passed to the provisioner and that there was no evidence of any impact to customer data it maintained.

    However, because the attacker’s infrastructure is outside the project’s control, Coder does not have access to crucial logs and cannot conclusively identify every compromised deployment.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    coders Compromised infrastructure Malicious modules Push registry
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories

    HPE patches critical ArubaOS-CX remote code execution flaw

    Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal

    Social Media Posts Push False Claim of Trump Chopping Down 60 Cherry Trees

    Microsoft: KB5120998 mouse reset bug affects only non-English PCs

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    JD Vance Says He Wouldn’t Call Iran Conflict a War

    September 3, 2026

    Startup ARR is less secure than ever, new research shows

    September 3, 2026

    Playco cut manual fixes 50% prototyping games with GPT-6 Astra

    September 3, 2026

    Coder’s registry infrastructure compromised to push malicious modules

    September 3, 2026
    Latest Posts

    Ultrafast X-rays capture chemistry unfolding atom by atom

    July 31, 2026

    How a PPE company’s highly publicized $32M Bitcoin strategy quietly expired without purchasing a single coin

    July 31, 2026

    Critical Flaw Led to Azure Cosmos DB Pwnage

    July 31, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    JD Vance Says He Wouldn’t Call Iran Conflict a War

    September 3, 2026

    Startup ARR is less secure than ever, new research shows

    September 3, 2026

    Playco cut manual fixes 50% prototyping games with GPT-6 Astra

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.