Coder hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Coder disclosed an infrastructure compromise of registry.coder.com that let attackers serve malicious Terraform modules to some users and potentially expose secrets on affected hosts. The altered delivery path ran through Cloudflare-backed infrastructure and affected requests made between 07:35 UTC and 21:45 UTC on Monday, August 31. Coder said the malicious files contained credential-stealing code and advised impacted users to rotate secrets, review logs, and purge cached packages.
Related Happenings
Malicious Terraform modules with credential-stealing code
Malware Activity
H score30
First: 03.09.2026 23:04
Last: 03.09.2026 23:04
Sources 1
How related:
Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
About this happening:
Malicious Terraform modules were delivered through a compromised registry and ran credential-stealing code, putting developer secrets and cloud credentials at risk. The mo...
Malicious Terraform modules with credential-stealing code
Malware ActivityHow related: Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code.
About this happening: Malicious Terraform modules were delivered through a compromised registry and ran credential-stealing code, putting developer secrets and cloud credentials at risk. The mo...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
TA416 European government espionage campaign
Campaign
H score32
First: 01.04.2026 15:05
Last: 01.04.2026 15:05
Sources 1
About this happening:
TA416 has resumed cyber espionage activity, targeting European governments and EU/NATO diplomatic missions with a renewed malware-delivery operation that raises cross-...
TA416 European government espionage campaign
CampaignAbout this happening: TA416 has resumed cyber espionage activity, targeting European governments and EU/NATO diplomatic missions with a renewed malware-delivery operation that raises cross-...
Latest development: 03.04.2026 20:34
TA416 expanded its espionage campaign to Middle Eastern government and diplomatic entities after the outbreak of the U.S.-Israel-Iran conflict in late February 2026, while linking to archives hosted on Google Drive or a compromised SharePoint instance to refine its PlugX delivery chain and collect regional intelligence.
Timeline
-
03.09.2026 23:04 2 articles · 1h ago
Coder hit by network compromise
Initial DisclosureAttackers accessed Coder’s Cloudflare-backed registry infrastructure and added unauthorized servers into the delivery path. The compromise began serving malicious Terraform modules to a subset of users during 07:35 UTC to 21:45 UTC on Monday, August 31.
Show sources
- Coder's registry infrastructure compromised to push malicious modules — www.bleepingcomputer.com — 03.09.2026 23:04
- Coder's registry infrastructure compromised to push malicious modules — www.bleepingcomputer.com — 03.09.2026 23:04