Skip to finding
§
High
Software supply chain
Confirmed

Coder's trusted module registry served credential-stealing Terraform modules after a Cloudflare API-key compromise.

Fetching a module during the exposure window was enough to run attacker code in the provisioner context.

Affects

Coder, self-hosted cloud-development-environment infrastructure whose Terraform modules execute in workspace provisioners

What it enables

Execution of attacker-supplied Terraform modules in trusted Coder provisioning workflows and theft of provisioner, cloud, CI, SSH, OIDC and database credentials

Use the compromised Cloudflare API key to add attacker-controlled IPs to registry.coder.com’s backend pool→↓Cloudflare routes a subset of legitimate registry requests to the malicious servers→↓A Coder deployment downloads a tampered module during template import, update, dry run or an uncached workspace build→↓Terraform invokes the module’s external telemetry script in the provisioner context→↓The script searches environment variables, configuration and terminal history and sends available credentials to coder-infra.com
Why this matters

This was an actual replacement of trusted provisioning artifacts, and correcting the registry origin did not remove cached modules or complete credential revocation.

Detail, proof-of-concept code and 3 sources
Required access

Control of a compromised Cloudflare API key capable of changing the registry origin pool; victims only had to fetch a trusted registry module during the exposure window

Affected versions

Coder versions below 2.37.0 using registry.coder.com during 2026-08-31 07:35–21:45 UTC, Remediated branch releases: 2.34.9, 2.35.7, 2.36.4 and 2.37.0

The compromised key added attacker-controlled origin IPs to registry.coder.com. When Cloudflare routed a module request there, Terraform invoked an external-data script that searched the provisioner environment and configuration for cloud, CI, SSH, OIDC and database credentials.

Previously fetched modules can remain in caches, and credential revocation was incomplete at publication. Coder supplied malicious hashes, an invocation marker and detection queries for finding affected artifacts.

Evidence
Coder confirms that a compromised Cloudflare API key redirected registry traffic to unauthorized servers serving malicious artifactsCoder documents the module execution contexts and the credentials exposed in each contextThe advisory publishes hashes, the Terraform invocation marker and detection queries for affected cached modules
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026