logo

CVE-2024-3094

ID: 28403a5d-7c23-53e6-9a44-f457bda8b39c

STIX ID: report--28403a5d-7c23-53e6-9a44-f457bda8b39c

Feed Name: Zscaler Security Research Blog

Threat Score
90/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes a sophisticated supply-chain attack that implants a backdoor into liblzma/XZ Utils test artifacts to modify SSHD behavior (CVE-2024-3094). The multi-stage payload targets Linux x86_64 builds, verifies environment variables, injects code into liblzma to alter RSA_public_decrypt, decrypts attacker payloads with ChaCha20 and verifies them with Ed448, and executes arbitrary commands on the SSH server before authentication; signatures are bound to the host public key so only the attacker can generate valid payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.