Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Compromise Coder Registry for Cloud Credential Theft

Hackers Compromise Coder Registry for Cloud Credential Theft

Posted on September 8, 2026 By CWS

A recent cybersecurity breach targeting Coder’s Terraform module registry has exposed numerous users to malicious packages designed to extract credentials from cloud development environments. This incident underscores significant vulnerabilities within infrastructure-as-code workflows.

Unauthorized Access and Traffic Redirection

The breach involved unauthorized alterations to Coder’s Cloudflare infrastructure, enabling cybercriminals to reroute registry traffic to their own servers. Coder’s security advisory disclosed that the attackers introduced unauthorized IP addresses into the infrastructure pool linked to the registry, thereby hosting altered Terraform artifacts that contained credential-stealing code.

This infiltration primarily affected Coder’s main registry, registry.coder.com, which serves as a critical resource for workspace templates and modules. The malicious packages were available to users between 07:35 UTC and 21:45 UTC on August 31, 2026.

Risks for Organizations and Users

Organizations could have been compromised if they engaged in creating or updating workspace templates, conducted template dry runs, or deployed workspaces during the vulnerability window, particularly if Terraform module caching was disabled. The injected code targeted secrets within the Terraform provisioner environment, aiming to capture and exfiltrate them to a remote server.

The attackers used a deceptive domain, coder-infra[.]com, to mimic legitimate Coder infrastructure, complicating detection during standard log reviews. The malicious modules reportedly executed a script via a data.external.telemetry block, communicating with a server at www[.]coder-infra[.]com/cli/check.

Mitigation and Response

Coder has assured that no customer data maintained by the company was impacted. They have released patched versions 2.37.0, 2.36.4, 2.35.7, and 2.34.9 of their software. Users are advised to clear potentially compromised modules from their caches and update to the latest versions.

Security teams are encouraged to audit Coder deployment records for module downloads during the breach and to scrutinize DNS, firewall, proxy, and VPC flow logs for any connections to coder-infra[.]com. Provisioner logs should be checked for the presence of data.external.telemetry, which could indicate execution of the malicious block.

Future Outlook and Supply-Chain Risks

The incident serves as a stark reminder of the supply-chain risks inherent in infrastructure-as-code practices. Even trusted registries can become vectors for credential theft when attackers compromise traffic-routing or package-distribution systems. Organizations are urged to rotate all potentially exposed credentials, including cloud API keys, CI/CD secrets, and other sensitive tokens.

For those seeking to enhance their cybersecurity posture, resources such as the AI SOC Deployment Playbook 2026 offer valuable insights into establishing metric-gated security operations centers powered by artificial intelligence.

Cyber Security News Tags:cloud credentials, cloud security, Coder, credential theft, Cybersecurity, Infrastructure, malicious modules, security breach, supply chain risk, Terraform

Post navigation

Previous Post: Grindr Settles U.K. Data Sharing Claims for £26 Million
Next Post: Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Related Posts

AI Safety Leadership in Flux as Director Resigns AI Safety Leadership in Flux as Director Resigns Cyber Security News
Enhancing SOC Efficiency by Reducing IOC Noise Enhancing SOC Efficiency by Reducing IOC Noise Cyber Security News
WhatsApp Enhances Security: 1 Billion Use Passkeys WhatsApp Enhances Security: 1 Billion Use Passkeys Cyber Security News
Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike Chinese State-Sponsored Hackers Attacking Semiconductor Industry with Weaponized Cobalt Strike Cyber Security News
10-Year-Old Roundcube RCE Vulnerability Let Attackers Execute Malicious Code 10-Year-Old Roundcube RCE Vulnerability Let Attackers Execute Malicious Code Cyber Security News
How Malicious AI Hijacks Victim Agents How Malicious AI Hijacks Victim Agents Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam
  • Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks
  • Hackers Compromise Coder Registry for Cloud Credential Theft
  • Grindr Settles U.K. Data Sharing Claims for £26 Million
  • Npm Worm Returns After 111 Days, Evades Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam
  • Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks
  • Hackers Compromise Coder Registry for Cloud Credential Theft
  • Grindr Settles U.K. Data Sharing Claims for £26 Million
  • Npm Worm Returns After 111 Days, Evades Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark