Agentic AI in the SOC: How to Move Faster Without Losing Control Register Now →

High

CA-A-26-035: Malicious Packages Served from Unauthorized Coder Registry Server

By Adversary Tactics and Intelligence Team

Estimated Reading Time: 4 minutes

Coder, software supply chain, registry compromise, Terraform modules, credential theft, GHSA-vx42-ghc9-gw65

Source Material: GitHub Security Advisory GHSA-vx42-ghc9-gw65; Coder v2.37.0 release notes | Technology: Coder self-hosted developer workspaces, Coder Registry modules, Terraform modules, Cloudflare-backed registry infrastructure | Targeted Industries: Organizations using Coder Registry modules; no industry-specific targeting publicly identified

Executive Summary

Coder published GHSA-vx42-ghc9-gw65 on September 1, 2026, describing a critical compromise of infrastructure used by the Coder module registry. An unidentified actor added unauthorized IP addresses to Coder’s Cloudflare-backed registry pool, causing registry[.]coder[.]com to serve malicious Terraform module artifacts to a subset of users.

Organizations may be impacted if a Coder deployment downloaded Coder Registry modules between 2026-08-31 07:35 and 21:45 UTC, particularly when creating or updating templates, running template dry runs, building workspaces from affected templates, or operating with Terraform module caching disabled. The malicious artifacts were designed to identify and exfiltrate credentials to a lookalike domain.

Security teams should urgently scope affected Coder deployments, clear potentially impacted cached modules, upgrade to a patched Coder release, review egress telemetry for the listed indicators, and rotate credentials that may have been available to Coder provisioners, coderd, workspace builds, cloud tooling, AI tooling, CI/CD tooling, or external auth providers.

Threat Overview and Strategic Impact

Coder disclosed that an unidentified malicious actor gained access to its Cloudflare infrastructure and added unauthorized IP addresses to the pool used by Coder’s module registry. During the reported window of 2026-08-31 07:35-21:45 UTC, registry[.]coder[.]com served malicious registry artifacts to a subset of users who fetched or updated Coder Registry modules. The malicious code was designed to locate credentials and send them to a lookalike domain, coder-infra[.]com.

The highest-risk organizations are ones using the main Coder module registry as a template source and that created or updated workspace templates, ran template dry runs, created workspaces from affected templates, or used deployments with Terraform module caching disabled during the exposure window. Coder reported no indication that customer data maintained by Coder was impacted, but affected self-hosted deployments may have exposed credentials present in provisioner environments, coderd configuration, workspace build contexts, terminal history, external-auth providers, cloud tooling, AI tooling, or CI/CD systems.

Strategically, this incident is a software supply-chain compromise against developer infrastructure. The impact is not limited to Coder availability; stolen credentials could enable follow-on access to cloud infrastructure, repositories, build systems, model gateways, or third-party developer tools. Organizations should treat exposure confirmation, credential rotation, and egress-log review as incident-response activities rather than routine patch management.

Security Hardening and Recommendations

Prioritize affected Coder environments immediately. Upgrade to Coder 2.37.0 or the supported patched branch release 2.36.4, 2.35.7, or 2.34.9. Before redeploying affected templates, clear potentially impacted cached modules using Coder’s published remediation guidance and verify which templates, template versions, dry runs, and workspace builds fetched modules during the exposure window. Rotate credentials that may have been accessible to provisioners, coderd, workspace runtime environments, external auth integrations, cloud SDKs, AI tooling, and CI/CD systems. Preserve relevant logs before retention windows expire and apply outbound network controls so developer infrastructure can only reach approved package registries and service endpoints.

Detection Strategy

Detections should focus on confirming whether affected Coder deployments fetched registry modules during the 2026-08-31 07:35-21:45 UTC window and whether any credential-exfiltration traffic occurred. Review Coder template-version, workspace-build, provisioner-job, DNS, proxy, firewall, VPC flow, and egress gateway logs. High-value signals include outbound requests to coder-infra[.]com, www.coder-infra[.]com, 199.91.220[.]205, or /cli/check; the X-CLI-Token header; unexpected execution of dlp.sh or dlp-docker.sh; and Coder provisioner logs containing data.external.telemetry. Where available, compare Coder module cache creation times against the vendor’s exposure window and investigate any workspaces created from affected templates.

How Deepwatch Protects Our Customers

Deepwatch Adversary Tactics & Intelligence is analyzing available intelligence for further technical details and exploitation telemetry associated with this activity. Our Guardians are continuously monitoring customer environments for signs of malicious or anomalous activity. Any identified suspicious activity undergoes immediate investigation in accordance with our response procedures.

Relevant Detections

Please visit Guardian Platform to access the relevant detections for this activity.

Technical Artifacts 

Please visit Guardian Platform to access the associated technical artifacts.

Threat Object Mapping

Intrusion Set:

  • Unknown / unattributed threat actor

Attack Pattern (MITRE ATT&CK/MITRE ATLAS):

TacticTechniqueTechnique IDAssociated Threat Activity
Initial AccessCompromise Software Supply ChainT1195.002Unauthorized registry infrastructure served malicious Terraform module artifacts to users who fetched modules during the exposure window.
Credential AccessCredentials In FilesT1552.001Malicious code was designed to identify cloud, CI/CD, AI tooling, and other credentials available to provisioners or workspaces.
ExfiltrationExfiltration Over C2 ChannelT1041Malicious scripts sent collected credentials to an attacker-controlled lookalike domain.

Vulnerabilities:

  • GHSA-vx42-ghc9-gw65; no CVE assigned as of the GitHub advisory

Malware/Tool:

  • Credential-stealing Coder registry module artifacts: dlp.sh and dlp-docker.sh

Additional Sources

Share

LinkedIn Twitter Facebook