A malicious supply-chain backdoor was discovered in XZ Utils versions 5.6.0 and 5.6.1, tracked as CVE-2024-3094, after PostgreSQL developer and Microsoft engineer Andres Freund investigated unusual CPU behavior and traced it to liblzma. The tampering was hidden in release tarballs rather than plainly visible in the main Git repository, using an obfuscated M4 macro during the build process to generate second-stage artifacts that altered library behavior. Researchers and vendors said the poisoned build could interfere with OpenSSH authentication through systemd, creating a path for unauthorized remote access to affected Linux systems.
Red Hat said Red Hat Enterprise Linux was not affected, but compromised packages reached Fedora Rawhide and Fedora Linux 40 beta, prompting urgent downgrade and rollback guidance to safe 5.4.x releases; Fedora 40 reportedly did not show successful execution of the injected code. Reports also said the malicious build succeeded in Debian unstable (Sid), appeared in a Debian beta branch, affected several openSUSE distributions, and was noted by Kali Linux, while stable Debian releases were not known to be impacted. The incident was widely described as a near-catastrophic attack on Linux infrastructure, with scrutiny falling on maintainer account Jia Tan / JiaT75 and an apparent long-running social-engineering effort to gain influence over the project.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository titled 'xz-malware' was published collecting material discovered during analysis of the malware hidden in xz Utils 5.6.0 and 5.6.1. The release added publicly accessible technical details to support deeper investigation of the backdoor.
A GitHub repository named 'distro-backdoor-scanner' was published to help identify Linux distribution systems exposed to the xz backdoor issue. The release added a practical detection tool for administrators and researchers responding to CVE-2024-3094.
Subsequent analysis attributed the malicious changes to the maintainer account JiaT75, also known as Jia Tan, and described a prolonged social-engineering effort to gain influence over the project. Additional likely fake identities were reported to have pressured original developer Lasse Collin to hand over more control.
Red Hat later reiterated that the malicious code was hidden in distribution tarballs rather than plainly in the main Git repository, and that Fedora 40 beta had received compromised packages without evidence of successful payload execution. The company urged administrators to audit systems for xz 5.6.0 and 5.6.1 and downgrade immediately.
Arch Linux published an official notice warning that the xz package had been backdoored following disclosure of CVE-2024-3094. The advisory added Arch Linux to the set of distributions publicly responding to the incident and provided distribution-specific guidance for users.
Following public disclosure, CISA issued an advisory on the xz backdoor as researchers and vendors assessed the scope of the compromise. Reporting noted concern that the operation may have involved a highly sophisticated or nation-state-linked actor.
Red Hat issued a critical warning that Fedora Rawhide and Fedora Linux 40 beta contained compromised xz packages, advised immediate downgrades to safe 5.4.x versions, and said Rawhide would be reverted. Red Hat also stated that Red Hat Enterprise Linux was not affected.
The malicious xz backdoor was assigned CVE-2024-3094 and reported with a critical severity, reflecting the risk of SSH authentication bypass and remote compromise on affected systems. Public reporting described the issue as a severe supply-chain attack on Linux infrastructure.
On 2024-03-29, Andres Freund identified abnormal CPU usage and traced the issue to liblzma, then disclosed the malicious backdoor publicly on the OpenWall security mailing list. His investigation exposed the compromise in xz 5.6.0 and 5.6.1.
Affected xz packages were introduced into Fedora Rawhide, Fedora Linux 40 beta, Debian unstable (Sid), Kali Linux, and some openSUSE distributions. Stable Debian releases and Red Hat Enterprise Linux were reported as not known to be affected.
Malicious code was inserted into xz Utils versions 5.6.0 and 5.6.1 via obfuscated build-time content in release tarballs, creating a supply-chain backdoor that altered liblzma behavior. The backdoored builds could interfere with OpenSSH authentication through systemd and potentially enable unauthorized remote access.
Before the malicious 2024 releases, the actor using the Jia Tan identity cultivated trust and increased influence within the xz project through sustained participation and social pressure around project maintenance. This preparatory access-building phase set the stage for the later insertion of the backdoored release artifacts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
26 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesuse.com
Open sourcegithub.com
Open sourceredhat.com
Open sourcehelpnetsecurity.com
Open sourcelwn.net
Open sourcelwn.net
Open sourceresearch.swtch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.