On August 31, 2026, threat actors compromised the Cloudflare account governing cloud development platform Coder, injecting unauthorized IP addresses into the origin pool for registry.coder.com. Over a fourteen-hour window, the rogue endpoints selectively intercepted inbound requests and delivered modified Terraform modules containing credential-harvesting code to engineers across enterprise and public-sector environments. Coder responded by removing the rogue IP addresses, terminating active administrative sessions, and distributing updated integrity hashes, though the breach underscores how upstream traffic tampering can outmaneuver otherwise vigilant cybersecurity defenses.