- Engineer — Act: If your teams use Coder’s Terraform registry, audit your module sources immediately and rotate any cloud credentials (AWS keys, GCP SAs, Azure SPNs) that Terraform may have accessed during runs while the malicious servers were active.
- SOC/IR — Act: Hunt CI/CD and IaC pipeline logs for module fetches from Coder’s registry during the compromise window; look for anomalous outbound credential-exfiltration traffic from Terraform runner environments and trigger an assume-breach sweep if usage is confirmed.
- Leader — Act: Determine whether engineering teams use Coder’s Terraform registry, and if so, request an incident timeline from Coder, assess credential exposure scope, and brief leadership on potential cloud environment impact before it surfaces externally.