logo

Assessing the Y, and How, of the XZ Utils incident

ID: 7501d16f-2fbc-51c3-8a56-d0878fa75b4c

STIX ID: report--7501d16f-2fbc-51c3-8a56-d0878fa75b4c

Feed Name: Securelist by Kaspersky

Threat Score
90/100

Date Published: 2024-04-24

Date Updated: 2026-04-29

Author: GReAT

...
...

This report examines a prolonged social-engineering supply-chain compromise of the XZ Utils open-source project, where multiple fictitious identities pressured the maintainer to add a co-maintainer and introduced obfuscated backdoor code (Feb–Mar 2024) designed to enable exclusive sshd access; the attackers then attempted to accelerate distribution of the backdoored upstream into major Linux distributions, with tactics and persistence comparable to major supply-chain incidents like SolarWinds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.