{
  "Event": {
    "uuid": "46e52090-0101-449a-87e4-440a47e6852a",
    "info": "When the Supply-Chain Attack Has No CVE: Inside the Coder Registry Hijack — Optimus Labs · Civilizations",
    "date": "2026-09-01",
    "threat_level_id": "1",
    "analysis": "2",
    "published": true,
    "Orgc": {
      "name": "Optimus Labs · Civilizations"
    },
    "Tag": [
      {
        "name": "optimus:briefing=\"coder-registry-infrastructure-hijack\""
      },
      {
        "name": "optimus:severity=\"critical\""
      },
      {
        "name": "optimus:type=\"supply-chain\""
      },
      {
        "name": "optimus:type=\"vendor-breach\""
      },
      {
        "name": "optimus:type=\"coding-agent\""
      },
      {
        "name": "optimus:category=\"SC\""
      },
      {
        "name": "optimus:category=\"AI\""
      },
      {
        "name": "optimus:category=\"AL\""
      },
      {
        "name": "optimus:category=\"AP\""
      },
      {
        "name": "type:OSINT"
      }
    ],
    "Attribute": [
      {
        "type": "link",
        "category": "External analysis",
        "to_ids": false,
        "value": "https://www.optimuslabs.io/research/briefings/coder-registry-infrastructure-hijack",
        "comment": "Optimus Labs briefing"
      },
      {
        "type": "link",
        "category": "External analysis",
        "to_ids": false,
        "value": "https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65",
        "comment": "Coder advisory GHSA-vx42-ghc9-gw65 — window, IoCs, SQL, rotation, patched builds"
      },
      {
        "type": "link",
        "category": "External analysis",
        "to_ids": false,
        "value": "https://registry.coder.com",
        "comment": "registry.coder.com — the delivery channel served maliciously"
      },
      {
        "type": "link",
        "category": "External analysis",
        "to_ids": false,
        "value": "https://answeroverflow.com/m/1544144200545865728",
        "comment": "Coder Discord #announcements (Sep 1) — second source"
      },
      {
        "type": "link",
        "category": "External analysis",
        "to_ids": false,
        "value": "https://github.com/coder/coder",
        "comment": "coder/coder — \"Secure environments for developers and their agents\""
      },
      {
        "type": "link",
        "category": "External analysis",
        "to_ids": false,
        "value": "https://coder.com/success-stories",
        "comment": "Coder success stories — install base"
      },
      {
        "type": "link",
        "category": "External analysis",
        "to_ids": false,
        "value": "https://github.com/coder/coder/security/advisories/GHSA-6x44-w3xg-hqqf",
        "comment": "CVE-2026-46354 (GHSA-6x44-w3xg-hqqf) — prior unauth PKCS#7 bypass, CVSS 9.1"
      },
      {
        "type": "link",
        "category": "External analysis",
        "to_ids": false,
        "value": "https://coder.com/docs",
        "comment": "Coder docs — platform, registry and agents"
      },
      {
        "type": "domain",
        "category": "Network activity",
        "to_ids": true,
        "value": "www.coder-infra.com",
        "comment": "Exfil domain: www[.]coder-infra[.]com (registered 2026-08-28)"
      },
      {
        "type": "ip-dst",
        "category": "Network activity",
        "to_ids": true,
        "value": "199.91.220.205",
        "comment": "Rogue registry IP: 199.91.220[.]205"
      },
      {
        "type": "filename",
        "category": "Payload delivery",
        "to_ids": false,
        "value": "dlp-docker.sh",
        "comment": "Payloads: dlp-docker.sh plus five dlp.sh variants"
      },
      {
        "type": "filename",
        "category": "Payload delivery",
        "to_ids": false,
        "value": "dlp.sh",
        "comment": "Payloads: dlp-docker.sh plus five dlp.sh variants"
      },
      {
        "type": "sha256",
        "category": "Payload delivery",
        "to_ids": true,
        "value": "7190a17c593276d7fd71c4863a4bc0b6c957ed14249288e6f64c5540e2c49398",
        "comment": "dlp-docker.sh SHA-256: 7190a17c593276d7fd71c4863a4bc0b6c957ed14249288e6f64c5540e2c49398"
      },
      {
        "type": "text",
        "category": "External analysis",
        "to_ids": false,
        "value": "GHSA-vx42-ghc9-gw65",
        "comment": "Advisory: GHSA-vx42-ghc9-gw65 (CVSS 9.0, no CVE). Patched: 2.37.0 / 2.36.4 / 2.35.7 / 2.34.9"
      }
    ]
  }
}