Nobody tampered with Coder's modules. They added IP addresses to the CDN pool so some requests went somewhere else
2026-09-05Security
For 14 hours on 31 August, registry.coder.com served Terraform modules from servers the attacker had inserted into Coder's Cloudflare origin pool. The packages at source were never touched, which defeats every control built around checking that an artifact is what the publisher published.