* [Docs](https://techdocs.akamai.com/home)

* [Sales](/why-akamai/contact-us/contact-sales)
* [Support](/global-services/support)
* [Under Attack ?](/why-akamai/stop-cyberthreats)

Login

Back
Login
Close

[Control Center   
Access the Akamai platform](https://control.akamai.com)

Back
Login
Close

[Cloud Manager   
Manage your cloud resources](https://login.linode.com/login)

* [Why Akamai](#)

  Back
  Why Akamai
  Close

  ##### Akamai Cloud

  Build low-latency, AI-driven applications with our affordable, open source cloud.

  [See cloud computing](/cloud)

  ##### Akamai Security

  Secure your applications and networks with real-time intelligence and adaptive AI.

  [See cybersecurity](/security)

  ##### Our global infrastructure

  Put AI experiences closer to users with the most distributed cloud platform and edge network.

  [See infrastructure](/why-akamai/global-infrastructure)

  + [Akamai Cloud](/cloud)
  + [Akamai Security](/security)
  + [Our global infrastructure](/why-akamai/global-infrastructure)
* [Products](#)

  Back
  Products
  Close

  1. Cloud Computing
  2. Cybersecurity
  3. Content Delivery
  4. [Global Services](/global-services)
  5. [All Products](/products)

  Back
  Cloud Computing
  Close

  + ARTIFICIAL INTELLIGENCE (AI)
  + [Akamai Inference Cloud](/products/akamai-inference-cloud-platform)

  + Compute
  + [Essential Compute](/products/essential-compute)
  + [GPU](/products/gpu)
  + [Accelerated Compute](/products/accelerated-compute)
  + [Kubernetes](/products/kubernetes)
  + [App Platform](/products/app-platform)

  + Serverless
  + [Akamai Functions](/products/akamai-functions)

  + Databases
  + [Managed Databases](/products/databases)

  + Storage
  + [Block Storage](/products/block-storage)
  + [Object Storage](/products/object-storage)
  + [Backups](/products/backups)

  + Networking
  + [Cloud Firewall](/products/cloud-firewall)
  + [DNS Manager](/products/dns-manager)
  + [NodeBalancers](/products/nodebalancers)
  + [Private Networking](/products/private-networking)

  + PRICING
  + [Pricing List](/cloud/pricing)

  Akamai Cloud

  [See cloud computing](/cloud)

  [See cloud computing](/cloud)

  Back
  Cybersecurity
  Close

  + app and api security
  + [API Security](/products/api-security)
  + [App & API Protector](/products/app-and-api-protector)
  + [Firewall for AI](/products/firewall-for-ai)
  + [Client-Side Protection & Compliance](/products/client-side-protection-compliance)

  + BOT & ABUSE PROTECTION
  + [Account Protector](/products/account-protector)
  + [Content Protector](/products/content-protector)
  + [Brand Protector](/products/brand-protector)
  + [Bot Manager](/products/bot-manager)

  + Segmentation
  + [Akamai Guardicore Platform](/products/akamai-guardicore-platform)
  + [Akamai Guardicore Segmentation](/products/akamai-guardicore-segmentation)

  + zero trust security
  + [Secure Internet Access](/products/secure-internet-access-enterprise)
  + [Akamai Hunt](/products/akamai-hunt)
  + [Enterprise Application Access](/products/enterprise-application-access)
  + [Akamai MFA](/products/akamai-mfa)

  + Infrastructure Security
  + [Edge DNS](/products/edge-dns)
  + [Prolexic](/products/prolexic-solutions)
  + [IP Accelerator](/products/ip-accelerator)
  + [DNS Posture Management](/products/akamai-dns-posture-management)

  Akamai Security

  [See cybersecurity](/security)

  [See cybersecurity](/security)

  Back
  Content Delivery
  Close

  + APPLICATION PERFORMANCE
  + [Ion](/products/web-performance-optimization)
  + [API Acceleration](/products/api-acceleration)
  + [IP Accelerator](/products/ip-accelerator)

  + Media Delivery
  + [Adaptive Media Delivery](/products/adaptive-media-delivery)
  + [Download Delivery](/products/download-delivery)

  + Edge Applications
  + [EdgeWorkers](/products/serverless-computing-edgeworkers)
  + [EdgeKV](/products/edgekv)
  + [Image & Video Manager](/products/image-and-video-manager)
  + [Media Services Live](/products/media-services-live)
  + [Cloudlets](/products/cloudlets)
  + [Cloud Wrapper](/products/cloud-wrapper)
  + [Global Traffic Management](/products/global-traffic-management)

  + MONITORING, REPORTING, AND TESTING
  + [DataStream](/products/datastream)
  + [mPulse](/products/mpulse-real-user-monitoring)
  + [CloudTest](/products/cloudtest)
* [Solutions](#)

  Back
  Solutions
  Close

  + Cloud Computing
  + [Serverless](/solutions/serverless)
  + [Media](/solutions/media)
  + [SaaS](/solutions/saas)
  + [Gaming](/solutions/gaming)

  + Security
  + [Cybersecurity Compliance](/solutions/cybersecurity-compliance)
  + [Ransomware Protection](/solutions/ransomware-protection)
  + [Secure Apps and APIs](/solutions/app-and-api-security)
  + [DNS Delivery and Security](/solutions/dns-delivery-and-security)
  + [Zero Trust](/solutions/zero-trust-security)
  + [DDoS Protection](/solutions/ddos-protection)
  + [Bot and Abuse Protection](/solutions/bot-and-abuse-protection)
  + [Identity, Credential, and Access Management](/solutions/identity-credential-and-access-management)

  + content delivery
  + [App and API Performance](/solutions/content-delivery-network/app-and-api-performance)
  + [Media Delivery](/solutions/content-delivery-network/media-delivery)
  + [Edge Compute](/solutions/edge)

  + industry solutions
  + [Media and Entertainment](/solutions/industries/media)
  + [Retail, Travel & Hospitality](/solutions/industries/retail-travel-hospitality)
  + [Financial Services](/solutions/industries/financial-services)
  + [Healthcare & Life Sciences](/solutions/industries/health-care-life-sciences)
  + [Public Sector](/solutions/industries/public-sector)
  + [Games](/solutions/industries/games)
  + [Online Sports Betting and iGaming](/solutions/industries/online-sports-betting)
  + [Service Providers](/solutions/industries/service-providers)
* [Resources](#)

  Back
  Resources
  Close

  + learning
  + [White papers, ebooks, videos, product briefs](/resources)
  + [Customer stories](/resources/customer-story)
  + [Training and certifications](/learn)

  + Cybersecurity Research
  + [Akamai Security Intelligence Group (SIG)](/security-research)
  + [State of the Internet (SOTI) reports](/security-research/the-state-of-the-internet)

  + cloud developers
  + [Developer hub](/cloud/developers)
  + [Guides and tutorials](https://www.linode.com/docs/guides/?utm_medium=website&utm_source=akamai)
  + [Cloud docs](https://techdocs.akamai.com/cloud-computing/docs/welcome)
  + [Community Q&A](https://www.linode.com/community/questions/?utm_medium=website&utm_source=akamai)
  + [Beta program](/cloud/beta-program)
  + [Start-up programs](/cloud/start-ups)

  + What’s new
  + [Akamai blog](/blog)
  + [Events and workshops](/resources/events)
* [Partners](#)

  Back
  Partners
  Close

  + Channel Partners
  + [Program overview](/channel-partners)
  + [Join Akamai Partner Connect](https://partners.akamai.com/registration/)
  + [Partner resources](/channel-partners/resources)
  + [Partner Portal](https://partners.akamai.com/)

  + technology partners
  + [Program overview](/technology-partners)

  + find a partner
  + [Channel Partner Directory](/channel-partners/directory)
  + [Technology Partner Directory](/technology-partners/directory)
  + [Partner stories](/resources/partner-story)

  + cloud marketplace
  + [Developer apps](/cloud/developers/apps)

Login

Back
Login
Close

[Control Center   
Access the Akamai platform](https://control.akamai.com)

Back
Login
Close

[Cloud Manager   
Manage your cloud resources](https://login.linode.com/login)

[Try Akamai](/products#free-trials)

[Under Attack?](/why-akamai/stop-cyberthreats)

# XZ Utils Backdoor — Everything You Need to Know, and What You Can Do

Written by

[Akamai Security Intelligence Group](/blog?author=akamai-security-intelligence-group)

April 01, 2024

Written by

[Akamai Security Intelligence Group](/blog?author=akamai-security-intelligence-group)

Share

CVE-2024-3094 is a vulnerability discovered in the open-source library XZ Utils that stems from malicious code that was pushed into the library by one of its maintainers.

## Executive summary

* [CVE-2024-3094](https://access.redhat.com/security/cve/CVE-2024-3094) is a vulnerability discovered in the open-source library XZ Utils that stems from malicious code that was pushed into the library by one of its maintainers.
* It was originally reported as an SSH authentication bypass backdoor, but [further analysis](https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b) indicates that the backdoor actually enables remote code execution (RCE).
* The threat actor started contributing to the XZ project almost two years ago, slowly building credibility until they were given maintainer responsibilities. Such long-term operations are usually the realm of state-sponsored threat actors, but specific attribution does not currently exist.
* Since the backdoor affects the latest XZ Utils releases, the recommended course of action is to downgrade to an uncompromised release. In this blog post, we offer other potential mitigations to limit the blast radius of the attack.

[Jump to action items](#detection-and-mitigation)

## Backstory

XZ Utils, and its underlying library liblzma, are open-source projects that implement the lzma compression and decompression. They are included in many Linux distributions out of the box, are very popular with developers, and are used extensively throughout the Linux ecosystem.

Almost two years ago, a developer under the name of Jia Tan joined the project and started opening pull requests for various bug fixes or improvements. So far, nothing is out of the ordinary; this is how things work in the open-source world. Eventually, after building trust and credibility, Jia Tan began to receive permissions for the repository — first, commit permissions and, eventually, release manager rights.

It seems that as part of the effort to gain these permissions, Jia Tan used an interesting form of [social engineering](https://x.com/robmen/status/1774067844785086775?s=20): They used fake accounts to send myriad feature requests and complaints about bugs to pressure the original maintainer, eventually causing the need to add another maintainer to the repository.

After contributing to the code for approximately two years, in 2023 Jia Tan introduced a few changes to XZ that were included as part of release 5.6.0. Among these changes was a sophisticated backdoor.

## The backdoor

The backdoor is quite complex. For starters, you won’t find it in the xz GitHub repository (which is currently disabled, but that’s besides the point). In what seems like an attempt to avoid detection, instead of pushing parts of the backdoor to the public git repository, the malicious maintainer only included it in source code tarball releases. This caused parts of the backdoor to remain relatively hidden, while still being used during the build process of [dependent projects](https://repology.org/project/xz/versions).

The backdoor is composed of many parts introduced over multiple commits:

* Using IFUNCs in the build process, which will be used to hijack the symbol resolve functions by the malware
* Including an obfuscated shared object hidden in [test files](https://git.tukaani.org/?p=xz.git;a=commitdiff;h=cf44e4b7f5dfdbf8c78aef377c10f71e274f63c0)
* Running a script set during the build process of the library that extracts the shared object (not included in the repository, only in releases, but added to [.gitignore](https://git.tukaani.org/?p=xz.git;a=blobdiff;f=m4/.gitignore;h=a7628601822c778d6ef01ad35d76e85cdb6a193c;hp=985c2800e8f991383b264edadba7ea1126f5db0b;hb=4323bc3e0c1e1d2037d5e670a3bf6633e8a3031e;hpb=5394a1665b7a108a54cb8b4ef3ebe59d3dbcca3a))
* [Disabling landlocking](https://git.tukaani.org/?p=xz.git;a=commitdiff;h=328c52da8a2bbb81307644efdb58db2c422d9ba7), which is a security feature to restrict process privileges

The execution chain also consists of multiple stages:

* The malicious script *build-to-host.m4* is run during the library’s build process and decodes the “test” file *bad-3-corrupt\_lzma2.xz* into a bash script
* The bash script then performs a more complicated decode process on another “test” file, *good-large\_compressed.lzma*, decoding it into another script
* That script then extracts a shared object *liblzma\_la-crc64-fast.o*, which is added to the compilation process of liblzma

This process is admittedly hard to follow. We recommend [Thomas Roccia](https://twitter.com/fr0gger_)’s [infographic](https://twitter.com/fr0gger_/status/1774342248437813525) for a great visual reference and in-depth analysis.

The shared object itself is compiled into liblzma, and replaces the regular function name resolution process. During (any) process loading, function names are resolved into actual pointers to the process memory, pointing at the binary code. The malicious library interferes with the function resolving process, so it could replace the function pointer for the OpenSSH function [RSA\_public\_decrypt](https://www.openssl.org/docs/manmaster/man3/RSA_public_decrypt.html) (Figure 1).

It then points that function to a malicious one of its own, which according to research published by [Filippo Valsorda](https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b), extracts a command from the authenticating client’s certificate (after verifying that it is the threat actor) and passes it on to the system() function for execution, thereby achieving RCE prior to authentication.

Fig. 1: The liblzma hooking process

For a more detailed explanation of the backdoor parts, you can read [Andres Freund](https://twitter.com/AndresFreundTec)'s [post on openwall](https://www.openwall.com/lists/oss-security/2024/03/29/4).

## Potential impact

**Currently, it appears as though the backdoor is added to the SSH daemon on the vulnerable machine, enabling a remote attacker to execute arbitrary code**. This means that any machine with the vulnerable package that exposes SSH to the internet is potentially vulnerable.

This backdoor almost became one of the most significant intrusion enablers ever — one that would’ve dwarfed the SolarWinds backdoor. The attackers were almost able to gain immediate access to any Linux machine running an infected distro, which includes Fedora, Ubuntu, and Debian. Almost.

There was only one thing that stopped that from happening — Andres Freund. After investigating a 500 ms latency issue that was introduced after a software update, Andres was able to trace the issue back to the xz package and ultimately identify the backdoor.

This obviously raises a lot of concerns. We got lucky. If this backdoor was not detected by a curious engineer, how long would it have remained active?

And perhaps even more concerning: What if this has happened before?

## Detection and mitigation

### Version control

The Cybersecurity and Infrastructure Security Agency [(CISA) recommended course of action](https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094) is to downgrade to an uncompromised version, such as 5.4.6.

To know which version of XZ Utils or liblzma you currently have on your systems, you can run the following query in [Akamai Guardicore Segmentation](/products/akamai-guardicore-segmentation) Insight that will look for loaded instances of the liblzma library (Figure 2).

```
  SELECT DISTINCT path AS liblzma_path
  FROM process_memory_map
  WHERE LOWER(path) LIKE "%liblzma%"
```

Fig. 2: Querying for loaded instances of liblzma

Alternatively, you can run the following query to find the package manager for the installed version.

```
  SELECT name AS vulnerable_item, 'DEB' AS type, version
  FROM deb_packages
  WHERE (LOWER(name) LIKE '%xz-utils%' OR LOWER(name) LIKE '%liblzma%')

  UNION

  SELECT name AS vulnerable_item, 'RPM' AS type, version
  FROM rpm_packages
  WHERE (LOWER(name) LIKE '%xz-utils%' OR LOWER(name) LIKE '%liblzma%')
```

Of course, you can also filter to show only vulnerable assets.

```
  SELECT path AS vulnerable_item, "Loaded Library" AS type, '5.6%' AS version
  FROM process_memory_map
  WHERE LOWER(path) LIKE "%liblzma%5.6%"
```

```
  SELECT name AS vulnerable_item, 'DEB' AS type, version
  FROM deb_packages
  WHERE (LOWER(name) LIKE '%xz-utils%' OR LOWER(name) LIKE '%liblzma%')
  AND version LIKE '5.6.%'

  UNION

  SELECT name AS vulnerable_item, 'RPM' AS type, version
  FROM rpm_packages
  WHERE (LOWER(name) LIKE '%xz-utils%' OR LOWER(name) LIKE '%liblzma%')
  AND version LIKE '5.6.%'
```

### Threat hunting

Since the backdoor actually executes system commands, and isn’t just allowing authentication, it might be possible to detect this behavior via process tracking.

Usually, during logon, a new shell is created for the logging user, and runs the default shell process (like bash). However, with this backdoor, the malicious command is actually executed by the SSH daemon process, *sshd*, which could trigger an anomaly.

Our threat hunting service, [Akamai Hunt](/products/akamai-hunt), has methods in place to detect such anomalies; for example, by constantly [tracking a baseline](/blog/security-research/novel-detection-methodology-process-injection-using-network-anomalies) of process activity and their child processes.

### Kill switch

According to [some analyses of the backdoor](https://gist.github.com/sgammon/ec604c3fabd1a22dd3cdc381b736b03e), it appears to have an environment variable kill switch. Adding the key *yolAbejyiejuvnup=Evjtgvsh5okmkAvj* to the system’s environment variables may disable the backdoor.

## References

* [Backdoor in upstream xz/liblzma leading to ssh server compromise](https://www.openwall.com/lists/oss-security/2024/03/29/4)
* [FAQ on the xz-utils backdoor](https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27#faq-on-the-xz-utils-backdoor)
* [Filippo Valsorda on X](https://bsky.app/profile/filippo.abyssdomain.expert/post/3kowjkx2njy2b)
* [CISA advisory](https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094)
* [RedHat CVE](https://access.redhat.com/security/cve/CVE-2024-3094)

[See more research](/security-research)

---

* [Cyber Security](/blog?filter=blogs/cyber-security)
* [Research](/blog?filter=blogs/research)
* [Threat Intelligence](/blog?filter=blogs/threat-intelligence)
* [Security Research](/blog?filter=blogs/security-research)
* [Akamai Guardicore Segmentation](/blog?filter=products/segmentation)
* [Akamai Hunt](/blog?filter=products/hunt)

Share

---

Written by

[Akamai Security Intelligence Group](/blog?author=akamai-security-intelligence-group)

April 01, 2024

Written by

[Akamai Security Intelligence Group](/blog?author=akamai-security-intelligence-group)

## Related Blog Posts

[On February 6, 2026, a full fix was deployed, completely eliminating the vulnerability from all Akamai services.](/blog/security-research/cve-2026-26365-incorrect-processing-connection-transfer-encoding)

Security Research

## CVE-2026-26365: Incorrect processing of “Connection: Transfer-Encoding”

February 20, 2026

Read how Akamai eliminated a potential HTTP request smuggling vector due to a bug in the processing of custom hop-by-hop HTTP headers.

by Akamai InfoSec

[Read more](/blog/security-research/cve-2026-26365-incorrect-processing-connection-transfer-encoding)

[PatchDiff-AI generated a detailed report that reveals insights about the vulnerable component and the attack vector.](/blog/security-research/inside-the-fix-cve-2026-21513-mshtml-exploit-analysis)

Security Research

## Inside the Fix: Analysis of In-the-Wild Exploit of CVE-2026-21513

February 20, 2026

Read how PatchDiff-AI uncovered the root cause of CVE-2026-21513 — an actively exploited MSHTML vulnerability — and how APT28 leveraged it in real-world attacks.

by Maor Dahan

[Read more](/blog/security-research/inside-the-fix-cve-2026-21513-mshtml-exploit-analysis)

[A new rule within Akamai App & API Protector has been deployed to protect our customers from this DoS threat.](/blog/security-research/cve-2026-23864-react-nextjs-denial-of-service)

Security Research

## CVE-2026-23864: React and Next.js Denial of Service via Memory Exhaustion

January 26, 2026

A newly disclosed vulnerability that affects multiple React-based frameworks reveals a denial-of-service flaw.

by Akamai Security Intelligence Group

[Read more](/blog/security-research/cve-2026-23864-react-nextjs-denial-of-service)

Rate the helpfulness of this page

* [Cloud Computing](/cloud)
* [Security](/security)
* [Content Delivery](/solutions/content-delivery-network)
* [All Products and Trials](/products)
* [Global Services](/global-services)

* [About Us](/company)
* [History](/company/company-history)
* [Leadership](/company/leadership)
* [Facts and Figures](/company/facts-figures)
* [Awards](/company/our-awards)
* [Board of Directors](/company/leadership/board-of-directors)
* [Infrastructure for Innovation](/why-akamai/infrastructure-for-innovation)
* [Investor Relations](https://www.ir.akamai.com/)
* [Corporate Responsibility](/company/corporate-responsibility)
* [Ethics](/company/ethics-and-compliance)
* [Locations](/company/locations)
* [Vulnerability Reporting](/global-services/support/vulnerability-reporting)
* [Accessibility Statement](/accessibility-statement)

* [Careers](/careers)
* [Working at Akamai](/careers/working-at-akamai)
* [Students and Recent Grads](/careers/students-and-recent-graduates)
* [Workplace Diversity](/careers/workplace-diversity)
* [Search Jobs](https://jobs.akamai.com/en/sites/CX_1)
* [Culture Blog](/blog/culture)

* [Newsroom](/newsroom)
* [Press Release](/newsroom/press-release)
* [In the News](/newsroom/in-the-news)
* [Media Resources](/newsroom/media-resources)

* [Legal](/legal)
* [Information Security Compliance](https://trust.akamai.com/)
* [Privacy Trust Center](https://trust.akamai.com/)
* [Privacy Statement](/legal/privacy-statement)
* [Cookie Settings](/legal/manage-cookie-preferences)
* [EU Digital Services Act (DSA)](/legal/eu-digital-services-act)

* [What Is API Security?](/glossary/what-is-api-security)
* [What Is a CDN?](/glossary/what-is-a-cdn)
* [What Is Cloud Computing?](/glossary/what-is-cloud-computing)
* [What Is Cybersecurity?](/glossary/what-is-cybersecurity)
* [What Is a DDoS attack?](/glossary/what-is-ddos)
* [What Is Microsegmentation?](/glossary/what-is-microsegmentation)
* [What Is WAAP?](/glossary/what-is-waap)
* [What Is Zero Trust?](/glossary/what-is-zero-trust)
* [See all](/glossary)

* [EMEA Legal Notice](/legal/emea-legal-notices)
* [Service Status](https://www.akamaistatus.com/)
* [Contact Us](/why-akamai/contact-us)

© 2026 Akamai Technologies