Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Coder

Coder Vendor Cyber Rating & Cyber Score

coder.au

Coder is an independent software engineering studio based in Sydney. We build websites, platforms, and custom software for founders and teams - from database schema to frontend to deployment. A tight network of senior engineers, modern stack, AI-native where it matters. No handoffs, no agency overhead. 20+ years of delivery experience behind every build, including work for the United Nations, NYU, Royal Bank of Canada, and Deutsche Telekom. Enterprise pedigree, founder pace.


Coder A.I CyberSecurity Scoring

Coder
Company Information
Website:https://coder.au
Employees number:1
Number of followers:8
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:coder.au
Coder Risk Score (AI oriented)
Between 700 and 749
logo
CoderTechnology, Information and Internet
Updated:
08/09/2026
740/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Coder Global Score (TPRM)
xxxx
logo
CoderTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CoderModerate
Current Score
740Ba (MODERATE)
01000
1 incidents
-31 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
771Before Incident
Cyber Attack
31 Aug 2026Coder
Coder: Hackers Hijack Coder Registry to Push Malicious Terraform Modules and Steal Cloud Credentials

Critical Supply-Chain Attack on Coder’s Terraform Registry Exposes Cloud Credentials

740After Incident
CRITICAL-31
COD1788855826
Critical Supply-Chain Attack on Coder’s Terraform Registry Exposes Cloud Credentials On August 31, 2026, Coder a provider of cloud development environments disclosed a security breach in its Terraform module registry, where attackers hijacked infrastructure to distribute malicious packages designed to steal credentials. The incident stemmed from unauthorized modifications to Coder’s Cloudflare configuration, allowing threat actors to redirect traffic from registry.coder.com to attacker-controlled servers between 07:35 UTC and 21:45 UTC. The rogue registry hosted tampered Terraform modules containing credential-stealing malware. The attack targeted organizations using Coder workspace templates, particularly those performing template imports, updates, dry runs, or workspace deployments with Terraform module caching disabled. The malicious code, embedded in a data.external.telemetry block, executed a script (dlp-docker.sh) that exfiltrated secrets including environment variables, OIDC tokens, SSH keys, and temporary authentication credentials to a lookalike domain, coder-infra[.]com (resolving to 199.91.220[.]205). The impact varied by deployment model. In standard provisioner environments, the malware accessed local secrets, while deployments running the provisioner within Coder’s main service risked exposure of database credentials, external authentication provider settings, and other application secrets. Coder confirmed no evidence of direct compromise to its customer data storage. To mitigate the threat, Coder released patched versions (2.37.0, 2.36.4, 2.35.7, 2.34.9) and advised users to: - Remove cached modules downloaded during the attack window. - Update to the latest secure versions. - Audit logs for connections to coder-infra[.]com or the data.external.telemetry string. - Rotate all potentially exposed credentials, including cloud API keys, CI/CD secrets, and SSH keys. The incident underscores the growing risk of supply-chain attacks in infrastructure-as-code workflows, where compromised registries can serve as vectors for credential theft. Security teams are urged to scrutinize trusted sources for similar threats.
INCIDENT DETAILS -
TYPE
Supply-Chain Attack
MOTIVATION
Credential Theft
IMPACT
Data Compromised: Environment variables, OIDC tokens, SSH keys, temporary authentication credentials, database credentials, external authentication provider settings, cloud API keys, CI/CD secretsSystems Affected: Terraform module registry, Coder workspace templates, provisioner environmentsOperational Impact: Potential exposure of sensitive credentials, required credential rotation and module updatesBrand Reputation Impact: HighIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Credentials, authentication tokens, SSH keys, database credentials, cloud API keys, CI/CD secretsSensitivity Of Data: HighData Exfiltration: Exfiltrated to *coder-infra[.]com* (199.91.220[.]205)Personally Identifiable Information: OIDC tokens, SSH keys, environment variables
AUGUST 2026
771Before Incident
JULY 2026
771Before Incident
JUNE 2026
771Before Incident
MAY 2026
771Before Incident
APRIL 2026
771Before Incident
MARCH 2026
771Before Incident
FEBRUARY 2026
771Before Incident
JANUARY 2026
771Before Incident
DECEMBER 2025
771Before Incident
NOVEMBER 2025
771Before Incident
OCTOBER 2025
771Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Coder ?
?
What was Coder's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Coder's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Coder's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Coder's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Coder's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Coder's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Coder's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Coder's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Coder's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Coder's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Coder's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Coder's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Coder ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Coder's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?