A malicious backdoor in XZ Utils versions 5.6.0 and 5.6.1 was identified as **CVE-2024-3094, with the tampering found in upstream release tarballs rather than the public Git repository. The compromised code targeted Linux distributions that linked liblzmainto patchedsshdbuilds, creating conditions for remote unauthorized access throughsystemd`-managed SSH authentication. Red Hat said affected packages appeared in Fedora Rawhide and Fedora 40 beta, while RHEL was not impacted, and it also cited evidence of successful malicious builds in Debian unstable (Sid).
Further analysis indicated the intrusion was a long-running open-source supply-chain operation tied to the contributor alias Jia Tan, using staged shell scripts and modified object files to activate malicious functionality during the build process. SentinelOne reported that 5.6.1 introduced a more modular mechanism capable of loading payloads from binary test files, suggesting the actor planned to add further vulnerabilities over time, and noted a suspicious February 2024 commit affecting LandLock as a possible sign of broader tampering. Vendors urged users to stop using affected Fedora builds and downgrade or revert to XZ 5.4.x while distributions investigated exposure and published recovery guidance.

Trace attribution and downstream blast radius.
10 events from the most recent confirmed update back to the earliest known activity.
On the oss-security mailing list, Andres Freund reported that upstream xz/liblzma 5.6.0 and 5.6.1 release artifacts were backdoored and could lead to OpenSSH server compromise. He described the malicious build-time script injection and said the behavior appeared to enable pre-auth unauthorized access or remote code execution under specific conditions.
A commit on February 28, 2024 broke the C program used to check LandLock support in xz utils, which the analysis flags as suspicious and potentially related to the attacker’s activity.
The actor operating under the alias Jia Tan began contributing to the xz project, marking the start of the long-running compromise effort described in the analysis.
As of March 30, 2024, Red Hat determined that Fedora Linux 40 beta contained affected xz library packages xz-libs-5.6.0-1.fc40.x86_64.rpm and xz-libs-5.6.0-2.fc40.x86_64.rpm, while noting the actual exploit did not appear active there.
An update reverting Fedora Linux 40 to xz 5.4.x was published through the normal update system as a mitigation for the malicious upstream packages.
Red Hat issued an urgent alert instructing Fedora Rawhide users to stop using affected instances and advising Fedora 40 users to downgrade to xz 5.4.x; it also stated that RHEL was unaffected.
The malicious xz issue was assigned CVE-2024-3094 after discovery of the backdoored code in upstream release tarballs.
Red Hat reported that malicious code intended to allow unauthorized access was discovered in upstream xz tools and libraries, specifically versions 5.6.0 and 5.6.1.
Version 5.6.1 added mechanisms to unpack and execute embedded scripts from test files during the build phase, expanding the attacker’s ability to deploy additional backdoors.
Version 5.6.0 of xz introduced repository code that enabled malicious backdoor injection during builds targeting Debian and Fedora distributions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
9 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcesentinelone.com
Open sourcembsd.jp
Open sourcencsc.nl
Open sourcehardenedvault.net
Open sourceredhat.com
Open sourcecve.org
Open sourceopenwall.com
Open sourcemail-archive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.