research!rsc: Timeline of the xz open source attack
Over a period of over two years, an attacker using the name “Jia Tan” worked as a diligent, effective contributor to the xz compression library, eventually being granted commit access and maintainership. Using that access, they installed a very subtle, carefully hidden backdoor into liblzma, a part of xz that also happens to be a dependency of OpenSSH sshd on Debian, Ubuntu, Fedora, and other systemd-based Linux systems. That backdoor watches for the attacker sending hidden commands at the start of an SSH session, giving the attacker the ability to run an arbitrary command on the target system without logging in: unauthenticated, targeted remote code execution. The attack was publicly disclosed on March 29, 2024 and appears to be the first serious known supply chain attack on widely used open source software. It marks a watershed moment in open source supply chain security, for better or worse. This post is a detailed timeline that I have constructed of the social engineering aspect of
research!rsc: Timeline of the xz open source attack research!rsc Thoughts and links about programming, by Russ Cox RSS Timeline of the xz open source attack Russ Cox April 1, 2024 Updated April 3, 2024. research.swtch.com/xz-timeline Posted on Monday, April 1, 2024. Updated Wednesday, April 3, 2024. Over a period of over two years, an attacker using the name “Jia Tan” worked as a diligent, effective contributor to the xz compression library, eventually being granted commit access and maintainership. Using that access, they installed a very subtle, carefully hidden backdoor into liblzma, a part
Explore this link on the map →saved by
related reading
- What we know about the xz Utils backdoor that almost infected the world - Ars Technicaarstechnica.com
- XZ Utils backdoor - Wikipediaen.wikipedia.org
- Everything I Know About the XZ Backdoorboehs.org
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Security incident disclosure — July 2026huggingface.co
- Backdoor (computing) - Wikipediaen.wikipedia.org
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- Zenbleedlock.cmpxchg8b.com
- Why I attacknicholas.carlini.com
- Ultralytics AI Library Hacked via GitHub for Cryptomining | Wiz Blogwiz.io
- We should all be using dependency cooldownsblog.yossarian.net
- The Dirty Pipe Vulnerability — The Dirty Pipe Vulnerability documentationdirtypipe.cm4all.com