flâneur — a map of the web's best reading

research!rsc: Timeline of the xz open source attack

research.swtch.com · 2,619 words · saved by 1 readers

Over a period of over two years, an attacker using the name “Jia Tan” worked as a diligent, effective contributor to the xz compression library, eventually being granted commit access and maintainership. Using that access, they installed a very subtle, carefully hidden backdoor into liblzma, a part of xz that also happens to be a dependency of OpenSSH sshd on Debian, Ubuntu, Fedora, and other systemd-based Linux systems. That backdoor watches for the attacker sending hidden commands at the start of an SSH session, giving the attacker the ability to run an arbitrary command on the target system without logging in: unauthenticated, targeted remote code execution. The attack was publicly disclosed on March 29, 2024 and appears to be the first serious known supply chain attack on widely used open source software. It marks a watershed moment in open source supply chain security, for better or worse. This post is a detailed timeline that I have constructed of the social engineering aspect of

research!rsc: Timeline of the xz open source attack research!rsc Thoughts and links about programming, by Russ Cox RSS Timeline of the xz open source attack Russ Cox April 1, 2024 Updated April 3, 2024. research.swtch.com/xz-timeline Posted on Monday, April 1, 2024. Updated Wednesday, April 3, 2024. Over a period of over two years, an attacker using the name “Jia Tan” worked as a diligent, effective contributor to the xz compression library, eventually being granted commit access and maintainership. Using that access, they installed a very subtle, carefully hidden backdoor into liblzma, a part

Explore this link on the map →

saved by

related reading