logo

Malicious Code in XZ Utils for Linux Systems Enables Remote Code Execution

ID: dd72127b-de6d-5711-96a6-80dcbdc0d444

STIX ID: report--dd72127b-de6d-5711-96a6-80dcbdc0d444

Feed Name: The Hacker News

Threat Score
95/100

Date Published: 2024-04-02

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

The report describes a sophisticated supply-chain compromise in the XZ Utils compression utility (tracked as CVE-2024-3094) where a project maintainer introduced a backdoor into released tarballs (5.6.0 and 5.6.1) that allows remote attackers with a predetermined private key to hijack the SSH daemon and execute arbitrary code; the intrusion involved multi-year social engineering, sockpuppet accounts, and is assessed as likely state-level in complexity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.