Coder: Cloudflare registry pool served malicious Terraform modules (31 Aug window)
Coder published GitHub advisory GHSA-vx42-ghc9-gw65 on 1 September 2026 (Critical). An unidentified actor gained access to Coder's Cloudflare infrastructure and added unauthorised IP addresses to the pool used for the Coder module registry (registry.coder.com). Those addresses hosted a malicious copy of registry artefacts. For a short window the registry served malicious packages to a subset of users. The implanted code was designed to identify credentials and exfiltrate them to a lookalike domain (coder-infra.com). Coder says it has no indication that any customer data maintained by Coder was impacted. Users who downloaded a Coder Registry module between 07:35 UTC and 21:45 UTC on Monday 31 August 2026 may be affected (new templates or template versions; also workspace creation if module caching is disabled). Coder recommends reviewing firewall, DNS and VPC logs for outbound traffic to coder-infra.com, purging cached modules from the affected window, rotating potentially exposed credentials, and updating Coder. Patched versions: 2.37.0, 2.36.4, 2.35.7, 2.34.9. Affected: versions before 2.37.0.
- Product
- Coder module registry (registry.coder.com)
- Versions
- Affected: Coder before 2.37.0; modules pulled 31 Aug 2026 07:35-21:45 UTC
- Exploited in Australia?
- unknown
- Patch to
- 2.37.0 / 2.36.4 / 2.35.7 / 2.34.9; purge cached modules from the window; rotate credentials; watch coder-infra.com egress
Primary: Coder GHSA-vx42-ghc9-gw65 (1 Sep 2026) ยท Vendor: Coder (vendor)
