Home / Companies / Coder / Blog / Post Details
Content Deep Dive

Coder Registry Security Incident: What Happened and What to Do

Blog post from Coder

Post Details
Company
Date Published
Author
-
Word Count
420
Company Posts That Month
6
Language
English
Hacker News Points
-
Post removed?
No
Summary

Coder disclosed that an unauthorized actor used a compromised Cloudflare API key to redirect some registry.coder.com traffic to a malicious server between 07:35 and 21:45 UTC on August 31, where tampered registry modules attempted to find and exfiltrate cloud credentials. The company said it remediated the incident the same day by removing malicious IPs, clearing caches, and confirming the registry was clean, while stating that its codebase and Google Cloud infrastructure were not compromised. Deployments may be affected if they downloaded modules during the incident window, particularly through new template or template-version creation or workspaces with module caching disabled. Coder advises customers to inspect network logs for outbound requests to coder-infra.com, use supplied SQL queries and remediation guidance in its GitHub security advisory, and update to the latest patched release, which includes automatic remediation steps.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.