logo

XZ Utils Backdoor Implanted in Carefully Executed, Multiyear Supply Chain Attack

ID: 7524255b-52cb-59fd-9702-56c18a37bdd5

STIX ID: report--7524255b-52cb-59fd-9702-56c18a37bdd5

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-04-01

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A malicious, maintainer-level backdoor was discovered in the liblzma component of XZ Utils (CVE-2024-3094), enabling attackers to bypass SSH authentication and obtain full system access. The backdoor was introduced via a long-term social-engineering campaign by a contributor who gained commit access; affected versions (5.6.0 and 5.6.1) appear in unstable/beta releases of several Linux distributions. Multiple vendors and CISA issued urgent advisories recommending downgrades or reverts, and tools/scanners have been released to detect the compromised binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.