YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0077

Incident record

Coder registry compromise exposes provisioning and AI-tool credentials

Severity
Critical
Status
Contained
Type
Data Leak
Target
Coder workspace registry and provisioners
Actor
attacker

What happened

Coder reports malicious registry packages served between 07:35 and 21:45 UTC on 31 August. Affected template operations and workspace builds could expose provisioner secrets and, in some cases, user tokens. Its 1 September advisory calls for cache cleanup, deployment updates and rotation of potentially exposed credentials, explicitly including AI-tool API keys. This is a developer supply-chain incident with AI-tool exposure; individual customer impact depends on activity during the affected window.

The advisory lists patched versions 2.37.0, 2.36.4, 2.35.7 and 2.34.9. Updating does not replace the documented cache cleanup or rotation of credentials potentially exposed during the affected window.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026