Everything I know about the XZ backdoor
Please note: This is being updated in real-time. The intent is to make sense of lots of simultaneous discoveries regarding this backdoor. last updated: 5:30 EST, on April 2nd
Everything I Know About the XZ Backdoor state evergreen in blog tags open-source date 3/29/2024 license CC BY-SA 4.0 This publication was last updated at 12:49 PM EST on April 8th Recently, a backdoor was discovered in XZ, a popular library for lossless data compression. Initial research efforts were predominantly concentrated on unpacking the well-disguised attack vector, while the social aspects of the attack received only murmurings. To investigate this attack, I never read a line of code. Instead, I spent dozens of hours pouring over hundreds of discussion threads and mailing lists. I’ve c
Explore this link on the map →related reading
- research!rsc: Timeline of the xz open source attackresearch.swtch.com
- XZ Utils backdoor - Wikipediaen.wikipedia.org
- What we know about the xz Utils backdoor that almost infected the world - Ars Technicaarstechnica.com
- Assessing Claude Mythos Preview’s cybersecurity capabilities \ Anthropicred.anthropic.com
- Security incident disclosure — July 2026huggingface.co
- Zenbleedlock.cmpxchg8b.com
- Why I attacknicholas.carlini.com
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown | Wiz Blogwiz.io
- ZPAQ - Wikipediaen.wikipedia.org
- Open Source is Not About You · GitHubgist.github.com
- Backdoor (computing) - Wikipediaen.wikipedia.org
- Playing the Open Source Game | Loris Cro's Blogkristoff.it