The attacker gained unauthorized access to Coder’s Cloudflare infrastructure and added attacker-controlled IP addresses to the pool serving Coder’s module registry. These servers hosted modified registry artifacts containing malicious code designed to discover credentials and exfiltrate them to the lookalike domain coder-infra[.]com. Users were potentially exposed when creating or updating templates during the incident window, as well as when creating workspaces from affected templates or when module caching was disabled.
The malicious artifacts included dlp.sh and dlp-docker.sh scripts, with a Terraform data "external" "telemetry" block used to invoke the latter. The malware targeted credentials accessible from affected environments, including cloud infrastructure API keys, AI tooling credentials, CI/CD credentials, environment variables, configuration files, and potentially credentials present in terminal history. Coder stated that it currently has no indication that customer data maintained directly by Coder was compromised.
Coder has released a new version that forces a clearing of the template cache to ensure that any malicious templates are deleted.