Multi-CloudIncident TeardownsRetrospectives

The XZ Utils Backdoor (Mar 2024): A Multi-Year Open-Source Supply-Chain Plot

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2024, written in 2026 with the benefit of hindsight.

On March 29, 2024, Microsoft engineer Andres Freund disclosed that he had found a backdoor in XZ Utils, a compression library included in many Linux distributions. He noticed while investigating why SSH logins were slightly slower and using more CPU than expected.

What happened

The backdoor (CVE-2024-3094) was inserted into XZ Utils versions 5.6.0 and 5.6.1. Through a chain involving systemd and OpenSSH on certain distributions, it could allow an attacker with a specific private key to execute code on affected systems via SSH — effectively a hidden master key.

A multi-year social engineering campaign

The backdoor was introduced by a contributor using the name "Jia Tan," who had spent about two years building trust in the project — contributing patches, helping the overloaded original maintainer and eventually gaining maintainer access. Other accounts appeared to pressure the original maintainer to add help. The malicious code was hidden in test files and build scripts rather than the main source code.

How close it came

The compromised versions had reached some testing and rolling-release distributions (such as Fedora Rawhide, Debian testing and unstable, Kali and others) but hadn't reached most stable enterprise distributions. Discovery came weeks before wider deployment.

Why it mattered

  • Open-source maintainers are often unpaid volunteers — a vulnerable point in the software supply chain.
  • Long-term social engineering can defeat code review.
  • Build-time tampering can hide from source review.
  • Luck played a significant role in discovery.

Lessons in hindsight

  • Know your open-source dependencies (SBOMs).
  • Scan images and containers for compromised versions.
  • Pin and verify dependency versions; avoid automatically pulling the latest.
  • Support critical open-source projects.
xz utils backdoor2024

More on this story