logo

Malicious xz backdoor reveals fragility of open source

ID: 4b16a82b-e306-5e26-ae11-551798bc90d7

STIX ID: report--4b16a82b-e306-5e26-ae11-551798bc90d7

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-04-01

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

**Executive summary:** A malicious backdoor was found in the xz/liblzma compression library that could allow remote code execution on vulnerable Linux systems by hooking into SSH via IFUNC/glibc; the backdoor was introduced across multiple commits (some appearing only in source tarballs) as part of a long-term infiltration and was caught early in a few bleeding-edge distributions (e.g., Fedora Rawhide/40, Debian Unstable, Kali). The report outlines the staged trust-building campaign against the maintainer, the technical mechanism and potential impact, and states attribution remains unconfirmed though the operation shows high sophistication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.