A malicious backdoor was discovered in XZ Utils, a widely used compression library, and assigned CVE-2024-3094, raising urgent concerns about software supply chain compromise across Linux environments. The tampered code was introduced into upstream release tarballs for versions 5.6.0 and 5.6.1 and could enable unauthorized remote code execution by subverting authentication workflows in systems using affected liblzma packages, particularly where sshd was linked through systemd integrations. Security teams were urged to identify vulnerable builds, downgrade to trusted versions, and verify package provenance across development and production systems.
The incident renewed attention on the broader risk posed by foundational open-source components becoming attack vectors, echoing the long-tail impact of major infrastructure flaws such as CVE-2021-44228 in Apache Log4j. While unrelated technically, both cases underscored how deeply embedded dependencies can create outsized enterprise exposure when compromised. Organizations were advised to strengthen software bill of materials validation, monitor upstream package integrity, and accelerate patching and rollback procedures for critical third-party libraries.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Seqrite published details on Operation DRAGONCLONE, describing a campaign targeting a Chinese telecom organization using VELETRIX and VShell malware. No earlier date for the campaign activity is provided in the reference block.
Seqrite published analysis of AsukaStealer, describing it as a low-cost malware offering priced at $80 and highlighting the threat it posed to users' digital security. The reference does not provide an earlier event date beyond the publication date.
A supply-chain compromise in XZ Utils was publicly disclosed as CVE-2024-3094, triggering broad security concern over the backdoored compression library. The reference indicates this disclosure had already occurred by the time of Seqrite's April 2024 write-up.
Ubuntu published a security notice page for CVE-2021-44228, documenting the vulnerability in its security tracker. The provided reference does not include additional event timing beyond the page's publication date.
3 references tracked. Mallory keeps watching after this page renders.
ubuntu.com
Open sourceseqrite.com
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.