{
  "type": "bundle",
  "id": "bundle--e9c7217c-0101-4176-8173-93ff6eac902f",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-01T00:00:00.000Z",
      "modified": "2026-09-01T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://www.optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--46e52090-0101-449a-87e4-440a47e6852a",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-01T00:00:00.000Z",
      "modified": "2026-09-01T00:00:00.000Z",
      "name": "When the Supply-Chain Attack Has No CVE: Inside the Coder Registry Hijack",
      "description": "An attacker hijacked Coder's own delivery infrastructure to serve credential-stealing modules from a trusted domain. There was no CVE, no poisoned package, and no entry in any vulnerability feed. Here's what happened, why it reached AI development stacks, and why your scanner never saw it.\n\nAn unidentified attacker gained access to Coder's Cloudflare infrastructure and added unauthorized IP addresses to the pool behind registry.coder.com. Those rogue servers hosted a tampered copy of the registry. For roughly fourteen hours, anyone who created or updated a template, ran a template dry-run, or deployed a workspace with module caching disabled pulled modules from a malicious registry — served from the real registry.coder.com domain. The tampered modules carried shell scripts — dlp.sh and dlp-docker.sh, invoked through a Terraform external data block — that scanned for credentials in environment variables, configuration files, and shell history, then exfiltrated them to a lookalike domain, coder-infra.com, registered three days before the attack.",
      "published": "2026-09-01T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Supply chain",
        "Vendor breach",
        "Coding agent",
        "Supply Chain nth Party Risk",
        "AI Asset Supply Chain Security",
        "Agentware Lifecycle Security",
        "Agent Permissions",
        "severity:critical"
      ],
      "object_refs": [
        "indicator--a8d214b4-0103-40c5-8562-e4b8fa9d5b57",
        "indicator--ae3f2ea4-0102-4679-850c-28723af41851",
        "indicator--b13af0bc-0102-424a-84fc-7dd0ab23dc30",
        "indicator--d2c85fb0-0102-48cb-82c3-59885d3ca987",
        "indicator--6bb94c50-0107-4efa-8abe-52aa6cc06b4a",
        "vulnerability--db4808a0-0100-4ccb-825b-7ab95dc48656",
        "software--f8fed034-0101-4742-8600-e88afa009776",
        "software--6ec1d894-0102-4107-8fc3-e9936fc4099b",
        "software--1d506540-0101-47b9-8c51-f2f91e51fcf9",
        "software--e1e62eb0-0101-44b3-81f1-845fde2e7c36",
        "software--5fd461a8-0101-4bda-8ed5-aa7260d62d82",
        "software--6b346830-0102-4e50-8a36-76606c368680",
        "software--03b6a3d0-0101-401d-82b7-73cd04b873ed",
        "software--0d9a2048-0101-47c3-8c9b-f78b0e9bf80b",
        "software--d01575e0-0101-44bf-82ee-b5ea1d1174a9",
        "software--0fe5ed04-0102-4c73-8ee7-f17710e80977"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://www.optimuslabs.io/research/briefings/coder-registry-infrastructure-hijack"
        },
        {
          "source_name": "Coder advisory GHSA-vx42-ghc9-gw65 — window, IoCs, SQL, rotation, patched builds",
          "url": "https://github.com/coder/coder/security/advisories/GHSA-vx42-ghc9-gw65"
        },
        {
          "source_name": "registry.coder.com — the delivery channel served maliciously",
          "url": "https://registry.coder.com"
        },
        {
          "source_name": "Coder Discord #announcements (Sep 1) — second source",
          "url": "https://answeroverflow.com/m/1544144200545865728"
        },
        {
          "source_name": "coder/coder — \"Secure environments for developers and their agents\"",
          "url": "https://github.com/coder/coder"
        },
        {
          "source_name": "Coder success stories — install base",
          "url": "https://coder.com/success-stories"
        },
        {
          "source_name": "CVE-2026-46354 (GHSA-6x44-w3xg-hqqf) — prior unauth PKCS#7 bypass, CVSS 9.1",
          "url": "https://github.com/coder/coder/security/advisories/GHSA-6x44-w3xg-hqqf"
        },
        {
          "source_name": "Coder docs — platform, registry and agents",
          "url": "https://coder.com/docs"
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--a8d214b4-0103-40c5-8562-e4b8fa9d5b57",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-01T00:00:00.000Z",
      "modified": "2026-09-01T00:00:00.000Z",
      "name": "domain: www.coder-infra.com",
      "description": "Exfil domain: www[.]coder-infra[.]com (registered 2026-08-28)",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[domain-name:value = 'www.coder-infra.com']",
      "pattern_type": "stix",
      "valid_from": "2026-09-01T00:00:00.000Z",
      "labels": [
        "coder-registry-infrastructure-hijack",
        "supply-chain",
        "vendor-breach",
        "coding-agent"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--ae3f2ea4-0102-4679-850c-28723af41851",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-01T00:00:00.000Z",
      "modified": "2026-09-01T00:00:00.000Z",
      "name": "ipv4: 199.91.220.205",
      "description": "Rogue registry IP: 199.91.220[.]205",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[ipv4-addr:value = '199.91.220.205']",
      "pattern_type": "stix",
      "valid_from": "2026-09-01T00:00:00.000Z",
      "labels": [
        "coder-registry-infrastructure-hijack",
        "supply-chain",
        "vendor-breach",
        "coding-agent"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--b13af0bc-0102-424a-84fc-7dd0ab23dc30",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-01T00:00:00.000Z",
      "modified": "2026-09-01T00:00:00.000Z",
      "name": "file: dlp-docker.sh",
      "description": "Payloads: dlp-docker.sh plus five dlp.sh variants",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[file:name = 'dlp-docker.sh']",
      "pattern_type": "stix",
      "valid_from": "2026-09-01T00:00:00.000Z",
      "labels": [
        "coder-registry-infrastructure-hijack",
        "supply-chain",
        "vendor-breach",
        "coding-agent"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--d2c85fb0-0102-48cb-82c3-59885d3ca987",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-01T00:00:00.000Z",
      "modified": "2026-09-01T00:00:00.000Z",
      "name": "file: dlp.sh",
      "description": "Payloads: dlp-docker.sh plus five dlp.sh variants",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[file:name = 'dlp.sh']",
      "pattern_type": "stix",
      "valid_from": "2026-09-01T00:00:00.000Z",
      "labels": [
        "coder-registry-infrastructure-hijack",
        "supply-chain",
        "vendor-breach",
        "coding-agent"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--6bb94c50-0107-4efa-8abe-52aa6cc06b4a",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-01T00:00:00.000Z",
      "modified": "2026-09-01T00:00:00.000Z",
      "name": "sha256: 7190a17c593276d7fd71c4863a4bc0b6c957ed14249288e6f64c5540e2c49398",
      "description": "dlp-docker.sh SHA-256: 7190a17c593276d7fd71c4863a4bc0b6c957ed14249288e6f64c5540e2c49398",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[file:hashes.'SHA-256' = '7190a17c593276d7fd71c4863a4bc0b6c957ed14249288e6f64c5540e2c49398']",
      "pattern_type": "stix",
      "valid_from": "2026-09-01T00:00:00.000Z",
      "labels": [
        "coder-registry-infrastructure-hijack",
        "supply-chain",
        "vendor-breach",
        "coding-agent"
      ]
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--db4808a0-0100-4ccb-825b-7ab95dc48656",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2026-09-01T00:00:00.000Z",
      "modified": "2026-09-01T00:00:00.000Z",
      "name": "GHSA-vx42-ghc9-gw65",
      "description": "Advisory: GHSA-vx42-ghc9-gw65 (CVSS 9.0, no CVE). Patched: 2.37.0 / 2.36.4 / 2.35.7 / 2.34.9",
      "external_references": [
        {
          "source_name": "github-advisory",
          "external_id": "GHSA-vx42-ghc9-gw65",
          "url": "https://github.com/advisories/GHSA-vx42-ghc9-gw65"
        }
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--f8fed034-0101-4742-8600-e88afa009776",
      "name": "Coder"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--6ec1d894-0102-4107-8fc3-e9936fc4099b",
      "name": "Cloudflare"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--1d506540-0101-47b9-8c51-f2f91e51fcf9",
      "name": "AWS"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--e1e62eb0-0101-44b3-81f1-845fde2e7c36",
      "name": "GCP"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--5fd461a8-0101-4bda-8ed5-aa7260d62d82",
      "name": "Azure"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--6b346830-0102-4e50-8a36-76606c368680",
      "name": "Anthropic"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--03b6a3d0-0101-401d-82b7-73cd04b873ed",
      "name": "OpenAI"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--0d9a2048-0101-47c3-8c9b-f78b0e9bf80b",
      "name": "GitHub"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--d01575e0-0101-44bf-82ee-b5ea1d1174a9",
      "name": "GitLab"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--0fe5ed04-0102-4c73-8ee7-f17710e80977",
      "name": "Bitbucket"
    }
  ]
}