A malicious backdoor was discovered in xz Utils, a widely used compression library embedded in many Linux distributions, after software engineer Andres Freund investigated unusual performance issues tied to ssh. Researchers said the tampered release could have allowed attackers to hijack SSH authentication and execute code on affected machines, creating a stealthy compromise path into Linux servers and downstream infrastructure. The affected version had been published but was not yet broadly deployed, and maintainers moved quickly to issue fixes after the disclosure.
Evidence cited by investigators indicates the attacker, operating under the pseudonym "Jia Tan," spent years building credibility in the open-source project before gaining maintainer influence and inserting the backdoor, making the incident one of the most serious recent software supply-chain threats. The operation's sophistication prompted speculation that a nation-state actor may have been involved, and the case renewed concern over covert interception techniques resembling earlier reports of man-in-the-middle targeting of major internet services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following disclosure, researchers said the sophistication of the operation suggested a highly capable actor, with some speculating that only a nation-state such as Russia or China could have carried it out. The true identity of the attacker remained unknown.
After Freund disclosed his findings, developers produced a fix for the compromised xz Utils release. The affected version had been published but was not yet widely deployed.
While investigating unusual SSH-related performance behavior during routine testing, software engineer Andres Freund identified the malicious backdoor in xz Utils. His discovery exposed what researchers described as a potentially massive and stealthy supply-chain attack.
A malicious backdoor was inserted into xz Utils, a compression library used on Linux systems. The backdoored release could have enabled attackers to hijack SSH connections and execute code on affected machines.
Evidence cited in the reference indicates the person using the pseudonym 'Jia Tan' spent years cultivating trust within the xz Utils open-source project before later becoming a maintainer. This long-term access set the stage for a supply-chain compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.