{"id":1384,"date":"2026-09-04T11:00:51","date_gmt":"2026-09-04T05:30:51","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1384"},"modified":"2026-09-07T11:52:59","modified_gmt":"2026-09-07T06:22:59","slug":"coder-registry-compromise","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/","title":{"rendered":"Coder Registry Compromise Pushed Credential-Stealing Terraform Modules"},"content":{"rendered":"<p>A Coder registry compromise turned a trusted developer module source into a credential-theft channel on August 31, 2026. An unidentified attacker gained access to Coder\u2019s Cloudflare infrastructure and added unauthorized IP addresses to the server pool behind <code>registry.coder.com<\/code>.<\/p>\n<p>Cloudflare consequently routed some legitimate registry requests to attacker-controlled servers. Those servers returned modified Coder registry artifacts containing malicious code. Coder says affected modules could collect cloud infrastructure credentials, AI-tooling API keys, CI\/CD credentials, OIDC tokens, SSH keys and other secrets available to provisioners.<\/p>\n<p>Coder published security advisory GHSA-vx42-ghc9-gw65, rated Critical with a CVSS v4.0 score of 9.0. GitHub lists Coder versions 2.37.0, 2.36.4, 2.35.7 and 2.34.9 as patched versions. It also instructs potentially affected users to identify and clear malicious cached modules before performing a fresh deployment and to update Coder.<\/p>\n<h2>Coder registry compromise at a glance<\/h2>\n<table style=\"font-weight: 400; width: 98.782%;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\" aria-colcount=\"2\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Detail<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><b><span data-contrast=\"auto\">Information<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Advisory<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><span data-contrast=\"auto\">GHSA-vx42-ghc9-gw65<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Affected service<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Coder module registry<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Registry<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><code><span data-contrast=\"auto\">registry.coder.com<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/code><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Incident type<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Software supply-chain compromise<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Severity<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Critical<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVSS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><span data-contrast=\"auto\">9.0, CVSS v4.0<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">CVE<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><span data-contrast=\"auto\">No known CVE<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Exposure window<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><span data-contrast=\"auto\">August 31, 2026, 07:35\u201321:45 UTC<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Malicious domain<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><code><span data-contrast=\"auto\">coder-infra[.]com<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/code><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Malicious IP<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><code><span data-contrast=\"auto\">199.91.220[.]205<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/code><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td style=\"width: 33.7531%;\" data-celllook=\"0\"><span data-contrast=\"auto\">Patched versions<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td style=\"width: 194.98%;\" data-celllook=\"0\"><span data-contrast=\"auto\">2.37.0, 2.36.4, 2.35.7, 2.34.9<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Coder says deployments may have been affected if they downloaded a Coder Registry module during the exposure window, primarily when creating new templates or template versions, or during workspace creation when module caching was disabled.<\/p>\n<h2>How the Coder registry compromise created a malicious delivery path<\/h2>\n<p>Coder Registry provides reusable Terraform modules that teams can add to Coder workspace templates. The templates themselves define the underlying workspace infrastructure, which can include environments such as cloud virtual machines, containers or Kubernetes workloads.<\/p>\n<p>The attacker did not simply create a convincing fake registry domain.<\/p>\n<p>Instead, Coder says the unidentified actor accessed its Cloudflare infrastructure. The attacker then added unauthorized IP addresses to the pool serving Coder&#8217;s module registry.<\/p>\n<p>Those IP addresses hosted a modified version of the registry containing malicious artifacts. Cloudflare subsequently directed some requests for the legitimate <code>registry.coder.com<\/code> service to those unauthorized servers.<\/p>\n<p>That distinction makes the attack particularly important.<\/p>\n<p>Users could request modules from the expected Coder registry hostname yet receive attacker-modified artifacts. If a deployment received an affected module, the malicious code could execute during template operations or a workspace build.<\/p>\n<h3>Coder identified two primary execution scenarios<\/h3>\n<p><strong>First<\/strong>, malicious modules could run when teams uploaded or updated templates or performed template dry runs. In this case, Coder says the primary exposure involved environment variables and secrets available on the provisioner.<\/p>\n<p><strong>Second<\/strong>, the malicious modules could run during a workspace build, when the provisioner receives additional secrets including the user&#8217;s OIDC token, a configured SSH key and single-use tokens for configured external authentication providers. Coder says refresh tokens are not passed to the provisioner.<\/p>\n<p>If the provisioner ran as part of <code>coderd<\/code> rather than as a separate service, Coder says this likely also leaked configuration variables such as the database password, external authentication provider information and other configuration.<\/p>\n<h2>What the Coder registry compromise put at risk<\/h2>\n<p>The malicious Terraform modules functioned as credential-stealing software rather than conventional destructive malware.<\/p>\n<p>According to Coder, potentially accessible information included:<\/p>\n<ul>\n<li>Provisioner environment variables and secrets<\/li>\n<li>Cloud infrastructure API keys<\/li>\n<li>AI-tooling API keys<\/li>\n<li>CI\/CD credentials<\/li>\n<li>Secrets stored in configuration files<\/li>\n<li>Terminal history<\/li>\n<li>User OIDC tokens<\/li>\n<li>Configured SSH keys<\/li>\n<li>One-time external authentication tokens<\/li>\n<li>Coder configuration secrets when provisioners ran within <code>coderd<\/code><\/li>\n<\/ul>\n<p>The malicious code used <code>dlp.sh<\/code> and <code>dlp-docker.sh<\/code> files. Coder also identified a Terraform <code>data.external.telemetry<\/code> block invoking the malicious script.<\/p>\n<p>The code was designed to exfiltrate collected credentials to <code>coder-infra[.]com<\/code>, a lookalike domain outside Coder&#8217;s control. This does not establish that data was successfully exfiltrated from every potentially affected deployment.<\/p>\n<p>This creates a wider problem than losing one developer password. A provisioner can sit at the intersection of development infrastructure, cloud services, CI\/CD systems and AI tooling.<\/p>\n<p>Secrets exposed there may therefore provide access to several separate systems.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/blogs\/wp-content\/uploads\/2026\/09\/How-to-Prevent-Supply-Chain-Attacks-with-XDR-Cover-Image-1024x535-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>How to Prevent Supply Chain Attacks with XDR<\/h4><p>Learn how XDR helps security teams detect suspicious activity and investigate supply-chain threats faster.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/how-to-prevent-supply-chain-attacks-with-xdr\/\" aria-label=\"How to Prevent Supply Chain Attacks with XDR\"><\/a><\/div><\/div><\/div>\n<h2>Why Coder cannot identify every affected deployment<\/h2>\n<p>The exposure window ran from 07:35 UTC until 21:45 UTC on August 31, 2026.<\/p>\n<p>However, downloading a module during that period does not automatically prove that a deployment received malicious code.<\/p>\n<p>Coder states that only a subset of users received the malicious artifacts. Because the rogue infrastructure belonged to the attacker, Coder does not possess the logs needed to conclusively determine every affected deployment.<\/p>\n<p>Potential exposure primarily applies to organizations that created new templates, updated template versions, ran template dry runs or deployed workspaces under relevant caching conditions during that window.<\/p>\n<p>Coder reported no indication that customer data maintained by Coder itself was affected.<\/p>\n<p>Organizations should therefore distinguish between potential exposure and confirmed credential loss during incident response.<\/p>\n<h2>How to investigate the Coder registry compromise<\/h2>\n<p>Coder recommends examining several telemetry sources before concluding that an environment was unaffected.<\/p>\n<p>Security and platform teams should review:<\/p>\n<ul>\n<li>Firewall logs<\/li>\n<li>Proxy logs<\/li>\n<li>DNS logs<\/li>\n<li>VPC flow logs<\/li>\n<\/ul>\n<p>Investigators should specifically search for outbound connections to <code>coder-infra[.]com<\/code>.<\/p>\n<p>Coder also recommends searching provisioner job logs for <code>data.external.telemetry<\/code>. This string can help identify execution associated with the malicious Terraform code.<\/p>\n<p>The advisory provides SQL queries for finding modules fetched during the exposure window and identifying associated templates or workspaces.<\/p>\n<p>Organizations should also clear potentially affected modules from Coder&#8217;s cache before performing fresh deployments.<\/p>\n<h2>Update Coder and rotate potentially exposed secrets<\/h2>\n<p>Coder lists 2.37.0, 2.36.4, 2.35.7 and 2.34.9 as patched versions.<\/p>\n<p>After investigating and clearing potentially malicious cached packages, organizations should update their Coder deployments to an appropriate patched release.<\/p>\n<p>Credential rotation is equally important.<\/p>\n<p>Coder specifically recommends rotating credentials that may have been accessible to workspace provisioners. Priority targets include:<\/p>\n<ul>\n<li>Cloud infrastructure API keys<\/li>\n<li>AI-tooling credentials<\/li>\n<li>CI\/CD secrets<\/li>\n<li>Secrets stored in environment variables<\/li>\n<li>Credentials in configuration files<\/li>\n<li>Credentials exposed through terminal history<\/li>\n<li>Affected OIDC or external authentication credentials<\/li>\n<li>SSH keys where applicable<\/li>\n<li>Coder configuration secrets potentially exposed through <code>coderd<\/code><\/li>\n<\/ul>\n<p>Rotation scope should reflect what each affected provisioner could actually access.<\/p>\n<h2>Where Hexnode fits into Coder incident response<\/h2>\n<p>The Coder supply-chain attack primarily requires investigation within Coder, its provisioners, network telemetry and potentially exposed cloud or developer credentials. Endpoint security controls provide an additional layer when affected infrastructure includes managed endpoints.<\/p>\n<p>Hexnode can strengthen security across managed developer endpoints, identity access and workstation posture, but DevOps teams must still update coderd and purge affected Coder module caches at the infrastructure layer.<\/p>\n<h3>Investigate suspicious activity on endpoints with Hexnode XDR<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> currently supports Windows and macOS endpoints and provides threat detection, investigation and response capabilities.<\/p>\n<p>If a potentially affected Coder component or related developer system runs on a managed endpoints, security teams can use Hexnode XDR to investigate suspicious endpoint activity associated with the incident.<\/p>\n<p>Hexnode XDR provides process-tree visibility and response actions including process termination, endpoint isolation and file quarantine. It also provides a query engine for threat hunting.<\/p>\n<p>These controls can support endpoint investigation and containment. However, Hexnode XDR does not replace Coder&#8217;s incident-specific remediation.<\/p>\n<p>Teams still need to inspect Coder and network logs, remove malicious cached modules, update Coder and rotate potentially exposed secrets.<\/p>\n<h3>Maintain security baselines on managed engineering endpoints with Hexnode UEM<\/h3>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can support the management of developer and administrator endpoints surrounding the affected environment.<\/p>\n<p>Documented capabilities include endpoint compliance, configuration policies, application management, OS and supported application updates, and advanced scripting.<\/p>\n<p>For example, IT administrators can use <a href=\"https:\/\/www.hexnode.com\/uem\/features\/hexnode-genie\/\">Hexnode Genie AI<\/a> to generate custom Bash scripts from natural-language instructions. Teams could create scripts to search supported managed endpoints for incident indicators such as <code>dlp.sh<\/code> or <code>dlp-docker.sh<\/code>, then review and validate the generated code before deployment. Hexnode&#8217;s scripting capabilities can also support diagnostic collection and organization-specific remediation tasks.<\/p>\n<p>However, Coder itself should be updated through the deployment or package workflow used by the organization. Hexnode UEM should not be positioned as automatically patching Coder or Terraform modules.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1-287x210.webp?format=webp 287w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1-96x100.webp?format=webp 96w\" sizes=\"auto, (max-width: 287px) 100vw, 287px\" title=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how combining UEM and XDR brings endpoint management, security context, threat investigation and incident response together.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h3>Restrict access from non-compliant devices<\/h3>\n<p>The stolen-secret risk also makes access control relevant after containment.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/idp\/\">Hexnode IdP<\/a> supports conditional access based on factors including user identity and device compliance. It also provides MFA and role-based access controls.<\/p>\n<p>Where protected developer, cloud or SaaS resources are integrated with the organization&#8217;s identity architecture, compliance-aware access policies can add another control around credential use.<\/p>\n<p>This does not invalidate a stolen credential or replace secret rotation. Potentially exposed credentials still need to be revoked or rotated according to Coder&#8217;s guidance.<\/p>\n<h2>What security teams should do after the Coder registry compromise<\/h2>\n<p>Organizations that used Coder Registry around the August 31 exposure window should prioritize incident-specific investigation.<\/p>\n<ol>\n<li><strong>Identify affected activity.<\/strong> Review template creation, template updates, dry runs and workspace builds during the exposure window.<\/li>\n<li><strong>Search for the exfiltration domain.<\/strong> Examine firewall, proxy, DNS and VPC flow logs for <code>coder-infra[.]com<\/code>.<\/li>\n<li><strong>Inspect provisioner logs.<\/strong> Search for <code>data.external.telemetry<\/code> and correlate findings with affected jobs and templates.<\/li>\n<li><strong>Identify cached modules.<\/strong> Use <a href=\"https:\/\/github.com\/coder\/coder\/security\/advisories\/GHSA-vx42-ghc9-gw65?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=coder_registry_compromise\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">Coder&#8217;s published queries<\/a> to locate modules downloaded during the exposure period.<\/li>\n<li><strong>Purge suspicious cached packages.<\/strong> Remove potentially malicious modules before redeploying workloads.<\/li>\n<li><strong>Update Coder.<\/strong> Move affected deployments to an appropriate patched release.<\/li>\n<li><strong>Rotate potentially exposed credentials.<\/strong> Prioritize cloud, AI, CI\/CD, OIDC, SSH and Coder-related secrets based on actual provisioner access.<\/li>\n<li><strong>Investigate relevant managed endpoints.<\/strong> Examine suspicious processes, files and connections where affected Coder components interacted with managed systems.<\/li>\n<li><strong>Review access controls.<\/strong> Limit sensitive application access according to identity, role and device posture where supported.<\/li>\n<\/ol>\n<h3>Trusted registries can become part of the attack path<\/h3>\n<p>The Coder incident demonstrates an unusual supply-chain failure: attackers inserted malicious infrastructure behind the legitimate registry service path.<\/p>\n<p>That allowed a normal request to <code>registry.coder.com<\/code> to return attacker-modified Terraform modules to some users.<\/p>\n<p>For affected organizations, remediation therefore extends beyond removing a malicious file. Teams need to identify potentially affected modules, templates and workspaces from the exposure window, investigate possible exfiltration and rotate credentials that may have been accessible to affected provisioners.<\/p>\n<p>Endpoint investigation, device management and identity controls can support that response. However, Coder&#8217;s own logs, indicators, cache-removal procedures, patched releases and credential-rotation guidance remain the primary remediation path.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen security across your managed endpoints<\/h5><p>Centralize endpoint management, enforce security baselines and strengthen visibility across the devices supporting your development environment.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Sign up now<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A Coder registry compromise turned a trusted developer module source into a credential-theft channel on&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1408,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[14,15],"class_list":["post-1384","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-supply-chain-attack","category-malware","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Coder Registry Compromise: Malicious Terraform Modules<\/title>\n<meta name=\"description\" content=\"The Coder registry compromise served malicious Terraform modules that targeted cloud, AI, CI\/CD, OIDC and SSH credentials.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Coder Registry Compromise: Malicious Terraform Modules\" \/>\n<meta property=\"og:description\" content=\"The Coder registry compromise served malicious Terraform modules that targeted cloud, AI, CI\/CD, OIDC and SSH credentials.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-04T05:30:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-07T06:22:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Coder Registry Compromise Pushed Credential-Stealing Terraform Modules\",\"datePublished\":\"2026-09-04T05:30:51+00:00\",\"dateModified\":\"2026-09-07T06:22:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/\"},\"wordCount\":1618,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp\",\"articleSection\":[\"Supply Chain Attack\",\"Malware\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/\",\"name\":\"Coder Registry Compromise: Malicious Terraform Modules\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp\",\"datePublished\":\"2026-09-04T05:30:51+00:00\",\"dateModified\":\"2026-09-07T06:22:59+00:00\",\"description\":\"The Coder registry compromise served malicious Terraform modules that targeted cloud, AI, CI\\\/CD, OIDC and SSH credentials.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"Coder Registry Compromise Pushed Credential-Stealing Terraform Modules\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/coder-registry-compromise\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Coder Registry Compromise Pushed Credential-Stealing Terraform Modules\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"description\":\"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Coder Registry Compromise: Malicious Terraform Modules","description":"The Coder registry compromise served malicious Terraform modules that targeted cloud, AI, CI\/CD, OIDC and SSH credentials.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/","og_locale":"en_US","og_type":"article","og_title":"Coder Registry Compromise: Malicious Terraform Modules","og_description":"The Coder registry compromise served malicious Terraform modules that targeted cloud, AI, CI\/CD, OIDC and SSH credentials.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-04T05:30:51+00:00","article_modified_time":"2026-09-07T06:22:59+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Coder Registry Compromise Pushed Credential-Stealing Terraform Modules","datePublished":"2026-09-04T05:30:51+00:00","dateModified":"2026-09-07T06:22:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/"},"wordCount":1618,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp","articleSection":["Supply Chain Attack","Malware"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/","url":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/","name":"Coder Registry Compromise: Malicious Terraform Modules","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp","datePublished":"2026-09-04T05:30:51+00:00","dateModified":"2026-09-07T06:22:59+00:00","description":"The Coder registry compromise served malicious Terraform modules that targeted cloud, AI, CI\/CD, OIDC and SSH credentials.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/Coder-Registry-Compromise-Pushed-Credential-Stealing-Terraform-Modules.jpeg?format=webp","width":1340,"height":754,"caption":"Coder Registry Compromise Pushed Credential-Stealing Terraform Modules"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/coder-registry-compromise\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Coder Registry Compromise Pushed Credential-Stealing Terraform Modules"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"description":"I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1384","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1384"}],"version-history":[{"count":3,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1384\/revisions"}],"predecessor-version":[{"id":1407,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1384\/revisions\/1407"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1408"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1384"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1384"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}