A supply chain attack targeted the Coder registry through compromised Cloudflare infrastructure, enabling malicious Terraform modules to be unknowingly served to developers from official domain addresses. The incident lasted approximately 14 hours on August 31 and exploited a vulnerability in the distribution system, allowing attackers to collect sensitive credentials (CI/CD keys, SSH keys, OIDC tokens, etc.) whenever an infected module was executed.
Organizations that engaged with the registry during this window are considered at risk. The attack received a critical CVSS rating of 9.0, and Coder advises affected users to inspect DNS and logs for potential breaches, and to rotate any compromised secrets. No breaches of stored customer data have been reported.