logo

500ms to midnight: XZ / liblzma backdoor

ID: 66dacdda-2f97-51da-b520-212dab57f3e9

STIX ID: report--66dacdda-2f97-51da-b520-212dab57f3e9

Feed Name: Elastic Security Labs

Threat Score
75/100

Date Published: 2024-04-05

Date Updated: 2026-04-27

...
...

On March 29, 2024 a maintainer-introduced backdoor was discovered in XZ Utils' liblzma (versions 5.6.0 and 5.6.1) via malicious build-script changes that decode and embed an obfuscated payload; the backdoor can bypass SSH authentication in a pre-auth context and was distributed in some builds and package channels. The impact was limited by low distribution and quick discovery, and Elastic published YARA signatures, osquery checks, and EQL detection rules while maintainers rolled affected packages back.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.