A supply-chain backdoor tracked as CVE-2024-3094 was inserted into upstream XZ Utils/liblzma release tarballs after the Jia Tan/JiaT75 persona spent years gaining contributor trust and commit access. Malicious build-time changes could, under narrow conditions, alter liblzma symbol resolution during OpenSSH public-key authentication, allowing attacker-controlled code to bypass authentication and obtain system-level SSH access with a specific key. Researcher Andres Freund uncovered the compromise after investigating anomalous SSH performance on Debian Sid.
The affected code reached development and pre-release channels, including Debian testing/unstable and Fedora Rawhide, but not stable production releases. The incident highlights the exposure created by lightly maintained open-source dependencies and social pressure directed at volunteer maintainers; organizations should inventory dependencies through SBOMs, assess project health and maintainer-access risks, analyze transitive dependencies, and favor supported stable/LTS releases for production systems.

Trace attribution and downstream blast radius.
8 events from the most recent confirmed update back to the earliest known activity.
Security researcher Andres Freund discovered the XZ/liblzma supply-chain backdoor after investigating unusually high sshd CPU usage during logins and Valgrind errors. The vulnerability was designated CVE-2024-3094.
A contributor using the JiaTan/JiaT75 persona joined the XZ project and began making contributions. The persona also built a history of contributions across open-source projects while gaining influence over XZ.
The event-stream npm compromise was discovered after Jayden Seric reported an unexpected package-deprecation warning and Node.js bootstrap error. A malicious flatmap-stream dependency added by maintainer right9ctrl contained obfuscated cryptocurrency-stealing code.
Elastic released YARA signatures, detection rules, and osquery queries to identify the XZ/liblzma backdoor and affected package versions. Elastic Defend deployed the Linux.Trojan.XZBackdoor YARA rule, and Elastic published an EQL behavioral detection for suspicious sshd child-process activity associated with simulated backdoor execution.
CISA advised organizations to downgrade XZ Utils to a version earlier than 5.6.0 and investigate systems on which affected releases had been installed for suspicious activity.
The compromised XZ code was incorporated into development or unstable channels including Debian Sid, Debian testing (trixie), Fedora Rawhide, and unstable releases associated with Red Hat, openSUSE, Kali, Arch, and Ubuntu. The affected channels were not stable production releases.
The compromise introduced obfuscated build-time logic into distributed XZ/liblzma source tarballs, modifying build artifacts and runtime symbol resolution. Under narrow conditions, it could redirect OpenSSH public-key authentication processing and enable an SSH authentication bypass.
After other accounts pressured the original maintainer to expand maintainership, Jia Tan gained author status and independent commit rights; the trust-building process took approximately two years. The original maintainer had reported social and mental-health difficulties.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
7 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourceelastic.co
Open sourcenodejs-security.com
Open sourcewiz.io
Open sourceaccess.redhat.com
Open sourcegithub.com
Open sourcetukaani.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.