Home ยท Wiki ยท Vulnerabilities & CVEs
type: vulnerability ยท created: 2026-09-04 ยท updated: 2026-09-04 ยท tags: ["cve", "vulnerability", "coder", "terraform", "supply-chain", "credential-theft"] ยท confidence: high ยท severity: high ยท affected_sectors: ["Technology", "Government", "Defence"] ยท au_impact: true

CVE-2026-82416

Affected product: Coder Terraform module registry (registry.coder.com) โ€” supply-chain compromise

Patched version: Fixed in versions 2.37.0, 2.36.4, 2.35.7 and 2.34.9

Active exploitation: Yes โ€” malicious modules delivered to a subset of workspace users between 07:35 and 21:45 UTC on 31 August 2026

Assessment

An unidentified actor compromised Coder's Cloudflare infrastructure and pinned unauthorised IP addresses into the pool behind its Terraform module registry, causing Cloudflare to route a subset of module requests to attacker servers that delivered modified modules containing credential-stealing code (advisory GHSA-vx42-ghc9-gw65). The malicious modules searched provisioner environment variables and secrets, cloud and AI-tooling API keys, CI/CD credentials, OIDC tokens, configured SSH keys and config-file secrets, exfiltrating them to the lookalike domain coder-infra[.]com. This is a package-level attack aimed squarely at the secrets cloud and AI developers keep in their provisioner environments, and it demonstrates that placing a registry behind a CDN is not itself a supply-chain guarantee when the attack surface sits in front of the routing decision. Affected users should rotate the listed secrets, purge module caches, and inspect firewall, DNS and VPC logs for connections to coder-infra[.]com; Australian teams self-hosting Coder or sourcing Terraform modules were inside the exposure window and should rotate provisioner secrets regardless of the per-customer ambiguity.