Sep 4 2026

Coder Registry Security Incident: What Happened and What to Do

Coder disclosed a security incident affecting its module registry on August 31, 2026. Learn what happened, who's affected, and how to remediate.

We want to be upfront with you about a security incident that affected Coder's module registry on Monday, August 31st, and what it may mean for your deployment.

What happened

Between 07:35 and 21:45 UTC on August 31st, an unauthorized actor compromised a Cloudflare API key and used it to redirect a portion of traffic from registry.coder.com to a malicious server they controlled. That server was serving tampered versions of Coder registry modules, ones designed to scan for and exfiltrate cloud credentials (AWS, GCP, Azure, and others) to an external domain.

We identified and fully remediated the issue within the same day. The malicious IPs have been removed, our cache has been cleared, and registry.coder.com is confirmed clean. Coder's own codebase and Google Cloud infrastructure were not compromised.

Does this affect me?

Your deployment may be affected if it pulled a module from the Coder Registry during the incident window. This most commonly happens when:

  • Creating a new template or template version
  • Creating a workspace with module caching disabled (caching is on by default, so this is less common)

If none of those activities happened during that window, you are very likely not affected.

What to do if you think you may be impacted

Start by checking your firewall, proxy, DNS, and VPC flow logs for any outbound traffic to coder-infra.com — that's the lookalike domain the malicious server used.

We've also provided SQL queries you can run directly against your Coder deployment to identify any affected cached modules or template versions. Full details, IOCs, and step-by-step remediation guidance are in our GitHub security advisory:
https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65

Patch releases are now available. We recommend updating to the latest version of Coder, which includes automatic remediation steps. You can find the releases at https://github.com/coder/coder/releases.

We're here to help

We know a notice like this can be stressful, especially when you're trying to determine whether your environment was affected. If you have questions, run into anything unexpected during remediation, or just want a second set of eyes - reach out to us at [email protected]. We are here to support our customers.

We're sorry this happened. We take security seriously, which can be seen from our regular security audits and penetration testing as part of our SOC 2 Type II program, and we are extending that same rigorous scrutiny to the third-party systems and infrastructure we rely on to ensure incidents like this don't happen again. You can find more information on controls, security posture, and attestations at trust.coder.com.

– The Coder Team

Coder Team
Coder Team

Coder Team

Subscribe to our newsletter

Want to stay up to date on all things Coder? Subscribe to our monthly newsletter for the latest articles, workshops, events, and announcements.