Tools AI Risk Radar ai-incident-0077
Incident record
Coder registry compromise exposes provisioning and AI-tool credentials
- Severity
- Critical
- Status
- Contained
- Type
- Data Leak
- Target
- Coder workspace registry and provisioners
- Actor
- attacker
What happened
Coder reports malicious registry packages served between 07:35 and 21:45 UTC on 31 August. Affected template operations and workspace builds could expose provisioner secrets and, in some cases, user tokens. Its 1 September advisory calls for cache cleanup, deployment updates and rotation of potentially exposed credentials, explicitly including AI-tool API keys. This is a developer supply-chain incident with AI-tool exposure; individual customer impact depends on activity during the affected window.
The advisory lists patched versions 2.37.0, 2.36.4, 2.35.7 and 2.34.9. Updating does not replace the documented cache cleanup or rotation of credentials potentially exposed during the affected window.
Sources
- Coder incident advisory and remediationgithub.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw…
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026