Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Compromise Coder Registry for Cloud Credential Theft

Hackers Compromise Coder Registry for Cloud Credential Theft

Posted on September 8, 2026 By CWS

A recent cybersecurity breach targeting Coder’s Terraform module registry has exposed numerous users to malicious packages designed to extract credentials from cloud development environments. This incident underscores significant vulnerabilities within infrastructure-as-code workflows.

Unauthorized Access and Traffic Redirection

The breach involved unauthorized alterations to Coder’s Cloudflare infrastructure, enabling cybercriminals to reroute registry traffic to their own servers. Coder’s security advisory disclosed that the attackers introduced unauthorized IP addresses into the infrastructure pool linked to the registry, thereby hosting altered Terraform artifacts that contained credential-stealing code.

This infiltration primarily affected Coder’s main registry, registry.coder.com, which serves as a critical resource for workspace templates and modules. The malicious packages were available to users between 07:35 UTC and 21:45 UTC on August 31, 2026.

Risks for Organizations and Users

Organizations could have been compromised if they engaged in creating or updating workspace templates, conducted template dry runs, or deployed workspaces during the vulnerability window, particularly if Terraform module caching was disabled. The injected code targeted secrets within the Terraform provisioner environment, aiming to capture and exfiltrate them to a remote server.

The attackers used a deceptive domain, coder-infra[.]com, to mimic legitimate Coder infrastructure, complicating detection during standard log reviews. The malicious modules reportedly executed a script via a data.external.telemetry block, communicating with a server at www[.]coder-infra[.]com/cli/check.

Mitigation and Response

Coder has assured that no customer data maintained by the company was impacted. They have released patched versions 2.37.0, 2.36.4, 2.35.7, and 2.34.9 of their software. Users are advised to clear potentially compromised modules from their caches and update to the latest versions.

Security teams are encouraged to audit Coder deployment records for module downloads during the breach and to scrutinize DNS, firewall, proxy, and VPC flow logs for any connections to coder-infra[.]com. Provisioner logs should be checked for the presence of data.external.telemetry, which could indicate execution of the malicious block.

Future Outlook and Supply-Chain Risks

The incident serves as a stark reminder of the supply-chain risks inherent in infrastructure-as-code practices. Even trusted registries can become vectors for credential theft when attackers compromise traffic-routing or package-distribution systems. Organizations are urged to rotate all potentially exposed credentials, including cloud API keys, CI/CD secrets, and other sensitive tokens.

For those seeking to enhance their cybersecurity posture, resources such as the AI SOC Deployment Playbook 2026 offer valuable insights into establishing metric-gated security operations centers powered by artificial intelligence.

Cyber Security News Tags:cloud credentials, cloud security, Coder, credential theft, Cybersecurity, Infrastructure, malicious modules, security breach, supply chain risk, Terraform

Post navigation

Previous Post: Grindr Settles U.K. Data Sharing Claims for £26 Million

Related Posts

One Identity Appoints Gihan Munasinghe as New CTO One Identity Appoints Gihan Munasinghe as New CTO Cyber Security News
ShinyHunters Breaches Canvas LMS via Free Accounts ShinyHunters Breaches Canvas LMS via Free Accounts Cyber Security News
Threat Actors Behind WARMCOOKIE Malware Added New Features to It’s Arsenal Threat Actors Behind WARMCOOKIE Malware Added New Features to It’s Arsenal Cyber Security News
Microsoft 365 North America Disruption Due to CDN Issue Microsoft 365 North America Disruption Due to CDN Issue Cyber Security News
SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely Cyber Security News
Seraphic Becomes the First and Only Secure Enterprise Browser Solution to Protect Electron-Based Applications Seraphic Becomes the First and Only Secure Enterprise Browser Solution to Protect Electron-Based Applications Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Compromise Coder Registry for Cloud Credential Theft
  • Grindr Settles U.K. Data Sharing Claims for £26 Million
  • Npm Worm Returns After 111 Days, Evades Detection
  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Compromise Coder Registry for Cloud Credential Theft
  • Grindr Settles U.K. Data Sharing Claims for £26 Million
  • Npm Worm Returns After 111 Days, Evades Detection
  • Innovative InjectEave Attack Eavesdrops on Headphones from 30 Meters
  • OpenAI Pledges $1 Billion for AI Cybersecurity Tools

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark