The XZ Utils backdoor is a malicious software supply-chain compromise tracked as CVE-2024-3094. It was embedded in the release build process for XZ Utils 5.6.0 and 5.6.1, causing a concealed payload to be incorporated into liblzma in targeted Linux distribution packages. The implant was designed to affect OpenSSH server processes indirectly linked to liblzma through distribution-specific systemd integration. Under its intended conditions, it subverted pre-authentication RSA-related processing in sshd and could permit remote code execution for an adversary holding the corresponding private key for an embedded public key. The backdoor used staged, obfuscated build-time reconstruction and environmental checks, including Linux, architecture, packaging, systemd, and sshd startup conditions, to limit activation and impede analysis. It also included an extension mechanism for additional payloads. The compromise was discovered by Andres Freund in March 2024 after investigation of anomalous sshd CPU activity, latency, and failures. The affected versions reached a limited set of rolling, testing, and experimental Linux distributions, rather than broad stable-release deployment. The malicious changes were committed under the JiaT75/Jia Tan contributor persona; the responsible individual or group has not been conclusively identified. No public exploitation cases were known at the time the compromise was disclosed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The backdoor is designed to circumvent authentication controls in sshd via systemd and attempts to execute code within a pre-authentication context.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The backdoor is designed to circumvent authentication controls in sshd via systemd and attempts to execute code within a pre-authentication context.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
The XZ Utils compromise fundamentally changed how many Linux developers and security teams think about package integrity. The attack wasn’t hidden inside obvious source code changes. Instead, malicious code was introduced into release artifacts that diverged from the reviewed source repository.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Supply-chain backdoor inserted into XZ Utils (notably versions 5.6.0/5.6.1) that impacted downstream Linux distributions briefly before removal; discussed in the context of auditing and detection methodology.
A highly obfuscated supply-chain backdoor inserted into XZ Utils (specifically liblzma/LZMA) that could be indirectly loaded by patched OpenSSH/sshd builds (e.g., systemd notification integration in some Linux distributions), enabling malicious behavior when specific packaging/build conditions were met and with self-deactivation/anti-analysis behaviors unless triggered under particular runtime conditions.
A malicious backdoor implanted into XZ Utils/liblzma via a supply-chain compromise. It hijacks pre-authentication RSA decryption in poisoned OpenSSH server binaries and enables remote code execution for an attacker possessing the matching private key.
A malicious backdoor embedded through compromised XZ Utils/liblzma build scripts in versions 5.6.0 and 5.6.1. It targets compatible Linux builds and can bypass SSH authentication controls to enable pre-authentication remote code execution through sshd.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.