The XZ Utils Backdoor (Mar 2024): A Multi-Year Open-Source Supply-Chain Plot
Retrospective: this article looks back at events from March 2024, written in 2026 with the benefit of hindsight.
On March 29, 2024, Microsoft engineer Andres Freund disclosed that he had found a backdoor in XZ Utils, a compression library included in many Linux distributions. He noticed while investigating why SSH logins were slightly slower and using more CPU than expected.
What happened
The backdoor (CVE-2024-3094) was inserted into XZ Utils versions 5.6.0 and 5.6.1. Through a chain involving systemd and OpenSSH on certain distributions, it could allow an attacker with a specific private key to execute code on affected systems via SSH — effectively a hidden master key.
A multi-year social engineering campaign
The backdoor was introduced by a contributor using the name "Jia Tan," who had spent about two years building trust in the project — contributing patches, helping the overloaded original maintainer and eventually gaining maintainer access. Other accounts appeared to pressure the original maintainer to add help. The malicious code was hidden in test files and build scripts rather than the main source code.
How close it came
The compromised versions had reached some testing and rolling-release distributions (such as Fedora Rawhide, Debian testing and unstable, Kali and others) but hadn't reached most stable enterprise distributions. Discovery came weeks before wider deployment.
Why it mattered
- Open-source maintainers are often unpaid volunteers — a vulnerable point in the software supply chain.
- Long-term social engineering can defeat code review.
- Build-time tampering can hide from source review.
- Luck played a significant role in discovery.
Lessons in hindsight
- Know your open-source dependencies (SBOMs).
- Scan images and containers for compromised versions.
- Pin and verify dependency versions; avoid automatically pulling the latest.
- Support critical open-source projects.
- How to Scan Cloud Images and Containers for Compromised Packages How-To & Hardening
- Detecting Compromised Open Source Packages: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Open-Source Dependencies Are Third-Party Risk CIO Briefings