logo

New XZ backdoor scanner detects implant in any Linux binary

ID: 4c9e73eb-9b70-5f9e-b519-9e27207c0f04

STIX ID: report--4c9e73eb-9b70-5f9e-b519-9e27207c0f04

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-04-02

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Binarly released a free online scanner and API (xz.fail) to detect a supply-chain backdoor (CVE-2024-3094) implanted in XZ Utils that leverages GCC IFUNC resolution to hook execution (observed in XZ 5.6.0/5.6.1); the article describes the backdoor's mechanism, limited exposure to bleeding-edge distributions, and Binarly's static-analysis approach to find IFUNC tampering across binaries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.