From Wikipedia, the free encyclopedia

Malicious software backdoor on Linux

XZ Utils backdoor

|  |
| --- |
| Previous XZ logo contributed by Jia Tan |
| [CVE identifier](/wiki/CVE_(identifier)) | [CVE](/wiki/CVE_(identifier))-[2024-3094](https://nvd.nist.gov/vuln/detail/CVE-2024-3094) |
| Date discovered | at or before 27 March 2024; 22 months ago (2024-03-27)[[1]](#cite_note-1)[[2]](#cite_note-2) |
| Date of public disclosure | 29 March 2024; 22 months ago (2024-03-29) |
| Date patched | 29 March 2024; 22 months ago (2024-03-29)[[a]](#cite_note-3)[[3]](#cite_note-4) |
| Discoverer | Andres Freund |
| Affected software | [xz](/wiki/XZ_Utils) / liblzma library |
| Website | [tukaani.org/xz-backdoor/](https://tukaani.org/xz-backdoor/) |

In February 2024, a [malicious](/wiki/Malware) [backdoor](/wiki/Backdoor_(computing)) was introduced to the Linux build of the [xz](/wiki/XZ_Utils) utility within the [liblzma](/wiki/Liblzma) library in versions 5.6.0 and 5.6.1 by an account using the name "Jia Tan".[[b]](#cite_note-5)[[4]](#cite_note-SamJames-6) The backdoor gives an attacker who possesses a specific [Ed448](/wiki/Ed448) private key [remote code execution](/wiki/Remote_code_execution) through [OpenSSH](/wiki/OpenSSH) on the affected Linux system. The issue has been given the [Common Vulnerabilities and Exposures](/wiki/Common_Vulnerabilities_and_Exposures) number [CVE](/wiki/CVE_(identifier))-[2024-3094](https://nvd.nist.gov/vuln/detail/CVE-2024-3094) and has been assigned a [CVSS](/wiki/Common_Vulnerability_Scoring_System) score of 10.0, the highest possible score.[[5]](#cite_note-7)

While xz is commonly present in most [Linux distributions](/wiki/Linux_distribution), at the time of discovery the backdoored version had not yet been widely deployed to [production](/wiki/Deployment_environment#Production) systems, but was present in development versions of major distributions.[[6]](#cite_note-8) The backdoor was discovered by the software developer Andres Freund, who announced his findings on 29 March 2024.[[7]](#cite_note-9)

## Background

[[edit](/w/index.php?title=XZ_Utils_backdoor&action=edit&section=1)]

Microsoft employee and [PostgreSQL](/wiki/PostgreSQL) developer Andres Freund reported the backdoor after investigating a [performance regression](/wiki/Software_regression#Performance_regressions) in [Debian Sid](/wiki/Debian_Sid).[[8]](#cite_note-10) Freund noticed that SSH connections were generating an unexpectedly high amount of CPU usage as well as causing errors in [Valgrind](/wiki/Valgrind),[[9]](#cite_note-:0-11) a memory debugging tool.[[10]](#cite_note-ars-what-we-know-12) Freund reported his finding to [Openwall Project](/wiki/Openwall_Project)'s open source security mailing list,[[9]](#cite_note-:0-11) which brought it to the attention of various software vendors.[[10]](#cite_note-ars-what-we-know-12) The attacker made efforts to [obfuscate](/wiki/Obfuscation_(software)) the code,[[11]](#cite_note-13) as the backdoor consists of multiple stages that act together.[[12]](#cite_note-register-14)

Once the compromised version is incorporated into the operating system, it alters the behavior of [OpenSSH](/wiki/OpenSSH)'s [SSH](/wiki/SSH) server daemon by abusing the [systemd](/wiki/Systemd) library, allowing the attacker to gain administrator access.[[12]](#cite_note-register-14)[[10]](#cite_note-ars-what-we-know-12) According to the analysis by [Red Hat](/wiki/Red_Hat), the backdoor can "enable a malicious actor to break sshd authentication and gain unauthorized access to the entire system remotely".[[13]](#cite_note-redhat-advisory-15)

A subsequent investigation found that the campaign to insert the backdoor into the [XZ Utils](/wiki/XZ_Utils) project was a culmination of approximately three years of effort, between November 2021 and February 2024,[[14]](#cite_note-jia-tan-wired-16) by a user going by the name *Jia Tan* and the nickname JiaT75 to gain access to a position of trust within the project. After a period of pressure on the founder and head maintainer to hand over the control of the project via apparent [sock puppetry](/wiki/Sock_puppetry), *Jia Tan* gained the position of co-maintainer of [XZ Utils](/wiki/XZ_Utils) and was able to sign off on version 5.6.0, which introduced the backdoor, and version 5.6.1, which patched some anomalous behavior that could have been apparent during software testing of the operating system.[[10]](#cite_note-ars-what-we-know-12)

Some of the suspected sock puppetry pseudonyms include accounts with usernames like *Jigar Kumar*, *krygorin4545*, and *misoeater91*. It is suspected that the names *Jia Tan*, as well as the supposed code author *Hans Jansen* (for versions 5.6.0 and 5.6.1), are pseudonyms chosen by the participants of the campaign. Neither have any sort of visible public presence in software development beyond the short few years of the campaign.[[15]](#cite_note-watching-17)[[16]](#cite_note-summary-timeline-18)[[17]](#cite_note-19)

The backdoor was notable for its level of sophistication and for the fact that the perpetrator practiced a high level of [operational security](/wiki/Operational_security) for a long period of time while working to attain a position of trust. American security researcher [Dave Aitel](/wiki/Dave_Aitel) has suggested that it fits the pattern attributable to [APT29](/wiki/APT29), an [advanced persistent threat actor](/wiki/Advanced_persistent_threat) believed to be working on behalf of the [Russian](/wiki/Russia) [Foreign Intelligence Service](/wiki/Foreign_Intelligence_Service_(Russia)) (SVR).[[14]](#cite_note-jia-tan-wired-16) Journalist Thomas Claburn suggested that it could be any state actor or a non-state actor with considerable resources.[[18]](#cite_note-xz-backdoor-theregister-20)

## Mechanism

[[edit](/w/index.php?title=XZ_Utils_backdoor&action=edit&section=2)]

The malicious code is known to be in 5.6.0 and 5.6.1 releases of the XZ Utils software package. The [exploit](/wiki/Exploit_(computer_security)) remains dormant unless a specific third-party patch of the SSH server is used. Under the right circumstances this interference could potentially enable a malicious actor to break sshd [authentication](/wiki/Authentication_protocol) and gain unauthorized access to the entire system [remotely](/wiki/Remote_access_service).[[13]](#cite_note-redhat-advisory-15) The malicious mechanism consists of two compressed test files that contain the malicious binary code. These files are available in the [git repository](/wiki/Git_repository), but remain dormant unless extracted and injected into the program.[[4]](#cite_note-SamJames-6) The code uses the [glibc](/wiki/Glibc) `IFUNC` mechanism to replace an existing function in [OpenSSH](/wiki/OpenSSH) called `RSA_public_decrypt` with a malicious version. OpenSSH normally does not load liblzma, but a common third-party [patch](/wiki/Patch_(computing)) used by several Linux distributions causes it to load [libsystemd](/wiki/Systemd), which in turn loads lzma.[[4]](#cite_note-SamJames-6) A modified version of `build-to-host.m4` was included in the release tar file uploaded on [GitHub](/wiki/GitHub), which extracts a script that performs the actual injection into `liblzma`. This modified [m4](/wiki/M4_(computer_language)) file was not present in the git repository; it was only available from [tar files](/wiki/Tar_file) released by the maintainer separate from git.[[4]](#cite_note-SamJames-6) The script appears to perform the injection only when the system is being built on an [x86-64](/wiki/X86-64) Linux system that uses glibc and [GCC](/wiki/GNU_Compiler_Collection) and is being built via [dpkg](/wiki/Dpkg) or [rpm](/wiki/RPM_Package_Manager).[[4]](#cite_note-SamJames-6)

## Response

[[edit](/w/index.php?title=XZ_Utils_backdoor&action=edit&section=3)]

### Remediation

[[edit](/w/index.php?title=XZ_Utils_backdoor&action=edit&section=4)]

The US federal [Cybersecurity and Infrastructure Security Agency](/wiki/Cybersecurity_and_Infrastructure_Security_Agency) issued a security advisory recommending that the affected devices should roll back to a previous uncompromised version.[[19]](#cite_note-21) Linux software vendors, including Red Hat, [SUSE](/wiki/SUSE_S.A.), and [Debian](/wiki/Debian), reverted the affected packages to older versions.[[13]](#cite_note-redhat-advisory-15)[[20]](#cite_note-22)[[21]](#cite_note-23) [GitHub](/wiki/GitHub) disabled the mirrors for the xz repository before subsequently restoring them.[[22]](#cite_note-24)

[Canonical](/wiki/Canonical_(company)) postponed the [beta release](/wiki/Beta_release) of [Ubuntu 24.04 LTS](/wiki/Ubuntu_version_history#2404) and its [flavours](/wiki/Ubuntu#Official_distributions) by a week and opted for a complete binary rebuild of all the distribution's packages.[[23]](#cite_note-25) Although the stable version of Ubuntu was not affected, [upstream](/wiki/Upstream_(software_development)) versions were. This precautionary measure was taken because Canonical could not guarantee by the original release deadline that the discovered backdoor did not affect additional packages during compilation.[[24]](#cite_note-26)

In August 2025, Binarly researchers found several Debian Docker images on Docker Hub that still have the XZ Utils backdoor.[[25]](#cite_note-Rudra2025-27)[[26]](#cite_note-githubdockerissue-28)[[27]](#cite_note-29) The Debian development team declined to remove the affected images, stating that they were development builds that should not be used on real systems in place of newer, clean container versions.[[26]](#cite_note-githubdockerissue-28)[[25]](#cite_note-Rudra2025-27)

### Broader response

[[edit](/w/index.php?title=XZ_Utils_backdoor&action=edit&section=5)]

Following the incident, the [Open Source Security Foundation](/wiki/Open_Source_Security_Foundation) (OpenSSF) and [OpenJS Foundation](/wiki/OpenJS_Foundation) issued a joint warning that the XZ Utils backdoor "may not be an isolated incident", reporting that similar social engineering attempts had targeted JavaScript projects hosted by OpenJS.[[28]](#cite_note-30) The foundations warned maintainers to watch for "friendly yet aggressive and persistent pursuit" by unknown community members seeking maintainer status.[[29]](#cite_note-31)

Computer scientist [Alex Stamos](/wiki/Alex_Stamos) opined that "this could have been the most widespread and effective backdoor ever planted in any software product", noting that had the backdoor remained undetected, it would have "given its creators a [master key](/wiki/Master_keying) to any of the hundreds of millions of computers around the world that run SSH".[[30]](#cite_note-nytimes-interview-32) In addition, the incident also started a discussion regarding the viability of having critical pieces of [cyberinfrastructure](/wiki/Cyberinfrastructure) depend on unpaid volunteers.[[31]](#cite_note-theverge-33)

## Notes

[[edit](/w/index.php?title=XZ_Utils_backdoor&action=edit&section=6)]

1. **[^](#cite_ref-3)** The vulnerability was effectively patched within hours of disclosure by reverting to a previous version known to be safe.
2. **[^](#cite_ref-5)** Whether Jia Tan is a group of people, a real name of a single person or a pseudonym of a single person is not known publicly.

## References

[[edit](/w/index.php?title=XZ_Utils_backdoor&action=edit&section=7)]

1. **[^](#cite_ref-1)** Freire, Rodrigo (30 April 2024). ["Understanding Red Hat's response to the XZ security incident"](https://www.redhat.com/en/blog/understanding-red-hats-response-xz-security-incident). *redhat.com*. Retrieved 14 August 2025.
2. **[^](#cite_ref-2)** ["Oxide and Friends 4/8/2024 -- Discovering the XZ Backdoor with Andres Freund"](https://www.youtube.com/watch?v=jg5F9UupL6I&t=1584s) (video). *youtube.com*. Oxide Computer Company. 14 August 2025.
3. **[^](#cite_ref-4)** Collin, Lasse. ["Remove the backdoor found in 5.6.0 and 5.6.1 (CVE-2024-3094)"](https://github.com/tukaani-project/xz/commit/e93e13c8b3bec925c56e0c0b675d8000a0f7f754). *GitHub*. Retrieved 19 June 2024.
4. ^ [***a***](#cite_ref-SamJames_6-0) [***b***](#cite_ref-SamJames_6-1) [***c***](#cite_ref-SamJames_6-2) [***d***](#cite_ref-SamJames_6-3) [***e***](#cite_ref-SamJames_6-4) James, Sam. ["xz-utils backdoor situation (CVE-2024-3094)"](https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27). *GitHub*. [Archived](https://web.archive.org/web/20240402010500/https://gist.github.com/thesamesam/223949d5a074ebc3dce9ee78baad9e27) from the original on 2 April 2024. Retrieved 2 April 2024.
5. **[^](#cite_ref-7)** Gatlan, Sergiu. ["Red Hat warns of backdoor in XZ tools used by most Linux distros"](https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/). *BleepingComputer*. [Archived](https://web.archive.org/web/20240329192759/https://www.bleepingcomputer.com/news/security/red-hat-warns-of-backdoor-in-xz-tools-used-by-most-linux-distros/) from the original on 29 March 2024. Retrieved 29 March 2024.
6. **[^](#cite_ref-8)** ["CVE-2024-3094"](https://nvd.nist.gov/vuln/detail/CVE-2024-3094). *[National Vulnerability Database](/wiki/National_Vulnerability_Database)*. NIST. [Archived](https://web.archive.org/web/20240402031933/https://nvd.nist.gov/vuln/detail/CVE-2024-3094) from the original on 2 April 2024. Retrieved 2 April 2024.
7. **[^](#cite_ref-9)** Corbet, Jonathan. ["A backdoor in xz"](https://lwn.net/Articles/967180/). *LWN*. [Archived](https://web.archive.org/web/20240401224317/https://lwn.net/Articles/967180/) from the original on 1 April 2024. Retrieved 2 April 2024.
8. **[^](#cite_ref-10)** Zorz, Zeljka (29 March 2024). ["Beware! Backdoor found in XZ utilities used by many Linux distros (CVE-2024-3094)"](https://www.helpnetsecurity.com/2024/03/29/cve-2024-3094-linux-backdoor/). *Help Net Security*. [Archived](https://web.archive.org/web/20240329192805/https://www.helpnetsecurity.com/2024/03/29/cve-2024-3094-linux-backdoor/) from the original on 29 March 2024. Retrieved 29 March 2024.
9. ^ [***a***](#cite_ref-:0_11-0) [***b***](#cite_ref-:0_11-1) Freund, Andres (29 March 2024). ["oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise"](https://www.openwall.com/lists/oss-security/2024/03/29/4). *www.openwall.com*. [Archived](https://web.archive.org/web/20240401131219/https://www.openwall.com/lists/oss-security/2024/03/29/4) from the original on 1 April 2024. Retrieved 14 August 2025.
10. ^ [***a***](#cite_ref-ars-what-we-know_12-0) [***b***](#cite_ref-ars-what-we-know_12-1) [***c***](#cite_ref-ars-what-we-know_12-2) [***d***](#cite_ref-ars-what-we-know_12-3) Goodin, Dan (1 April 2024). ["What we know about the xz Utils backdoor that almost infected the world"](https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/). *Ars Technica*. [Archived](https://web.archive.org/web/20240401072048/https://arstechnica.com/security/2024/04/what-we-know-about-the-xz-utils-backdoor-that-almost-infected-the-world/) from the original on 1 April 2024. Retrieved 1 April 2024.
11. **[^](#cite_ref-13)** O'Donnell-Welch, Lindsey (29 March 2024). ["Red Hat, CISA Warn of XZ Utils Backdoor"](https://duo.com/decipher/red-hat-warns-of-malicious-code-in-xz-utils). *Decipher*. [Archived](https://web.archive.org/web/20240329204451/https://duo.com/decipher/red-hat-warns-of-malicious-code-in-xz-utils) from the original on 29 March 2024. Retrieved 29 March 2024.
12. ^ [***a***](#cite_ref-register_14-0) [***b***](#cite_ref-register_14-1) Claburn, Thomas (29 March 2024). ["Malicious backdoor spotted in Linux compression library xz"](https://www.theregister.com/2024/03/29/malicious_backdoor_xz/). *The Register*. [Archived](https://web.archive.org/web/20240401022057/https://www.theregister.com/2024/03/29/malicious_backdoor_xz/) from the original on 1 April 2024. Retrieved 14 August 2025.
13. ^ [***a***](#cite_ref-redhat-advisory_15-0) [***b***](#cite_ref-redhat-advisory_15-1) [***c***](#cite_ref-redhat-advisory_15-2) ["Urgent security alert for Fedora 41 and Fedora Rawhide users"](https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users). Red Hat. 29 March 2024. [Archived](https://web.archive.org/web/20240329172128/https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users) from the original on 29 March 2024. Retrieved 14 August 2025.
14. ^ [***a***](#cite_ref-jia-tan-wired_16-0) [***b***](#cite_ref-jia-tan-wired_16-1) Greenberg, Andy (3 April 2024). ["The Mystery of 'Jia Tan,' the XZ Backdoor Mastermind"](https://www.wired.com/story/jia-tan-xz-backdoor/). *Wired*. [Archived](https://web.archive.org/web/20240403141041/https://www.wired.com/story/jia-tan-xz-backdoor/) from the original on 3 April 2024. Retrieved 3 April 2024.
15. **[^](#cite_ref-watching_17-0)** Tumbleson, Connor (31 March 2024). ["Watching xz unfold from afar"](https://connortumbleson.com/2024/03/31/watching-xz-unfold-from-afar/). *connortumbleson.com*. [Archived](https://web.archive.org/web/20240406063707/https://connortumbleson.com/2024/03/31/watching-xz-unfold-from-afar/) from the original on 6 April 2024. Retrieved 14 August 2025.
16. **[^](#cite_ref-summary-timeline_18-0)** ["Timeline summary of the backdoor attack on XZ Utils"](https://gigazine.net/gsc_news/en/20240403-timeline-of-xz-open-source-attack). *gigazine.net*. 3 April 2024. [Archived](https://web.archive.org/web/20240410211550/https://gigazine.net/gsc_news/en/20240403-timeline-of-xz-open-source-attack) from the original on 10 April 2024. Retrieved 14 August 2025.
17. **[^](#cite_ref-19)**  Cox, Russ (1 April 2024). ["Timeline of the xz open source attack"](https://research.swtch.com/xz-timeline). *research.swtch.com*. Retrieved 14 August 2025.
18. **[^](#cite_ref-xz-backdoor-theregister_20-0)** Claburn, Thomas. ["Malicious xz backdoor reveals fragility of open source"](https://www.theregister.com/2024/04/01/xz_backdoor_open_source/). *The Register*. [Archived](https://web.archive.org/web/20240408003643/https://www.theregister.com/2024/04/01/xz_backdoor_open_source/) from the original on 8 April 2024. Retrieved 8 April 2024.
19. **[^](#cite_ref-21)** ["Reported Supply Chain Compromise Affecting XZ Utils Data Compression Library, CVE-2024-3094"](https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094). CISA. 29 March 2024. [Archived](https://web.archive.org/web/20240329182032/https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094) from the original on 29 March 2024. Retrieved 29 March 2024.
20. **[^](#cite_ref-22)** Meissner, Marcus (27 December 2024). ["SUSE addresses supply chain attack against xz compression library"](https://www.suse.com/c/suse-addresses-supply-chain-attack-against-xz-compression-library/). *SUSE Communities*. SUSE. [Archived](https://web.archive.org/web/20240329215538/https://www.suse.com/c/suse-addresses-supply-chain-attack-against-xz-compression-library/) from the original on 29 March 2024. Retrieved 14 August 2025.
21. **[^](#cite_ref-23)** Salvatore, Bonaccorso (29 March 2024). ["[SECURITY] [DSA 5649-1] xz-utils security update"](https://lists.debian.org/debian-security-announce/2024/msg00057.html). *debian-security-announce* (Mailing list). [Archived](https://web.archive.org/web/20240329171247/https://lists.debian.org/debian-security-announce/2024/msg00057.html) from the original on 29 March 2024. Retrieved 29 March 2024.
22. **[^](#cite_ref-24)** Choudhary, Shrishti (30 March 2024). ["Important information regarding xz-utils (CVE-2024-3094)"](https://about.gitlab.com/blog/2024/03/30/important-information-regarding-xz-utils-cve-2024-3094). *about.gitlab.com*. [Archived](https://web.archive.org/web/20240401194824/https://about.gitlab.com/blog/2024/03/30/important-information-regarding-xz-utils-cve-2024-3094/) from the original on 1 April 2024. Retrieved 14 August 2025.
23. **[^](#cite_ref-25)** ["Noble Numbat Beta delayed (xz/liblzma security update)"](https://discourse.ubuntu.com/t/noble-numbat-beta-delayed-xz-liblzma-security-update/43827). *Ubuntu Community Hub*. 3 April 2024. [Archived](https://web.archive.org/web/20240410120702/https://discourse.ubuntu.com/t/noble-numbat-beta-delayed-xz-liblzma-security-update/43827) from the original on 10 April 2024. Retrieved 10 April 2024.
24. **[^](#cite_ref-26)** Sneddon, Joey (3 April 2024). ["Ubuntu 24.04 Beta Delayed Due to Security Issue"](https://www.omgubuntu.co.uk/2024/04/ubuntu-24-04-beta-delayed). *OMG! Ubuntu*. [Archived](https://web.archive.org/web/20240408084344/https://www.omgubuntu.co.uk/2024/04/ubuntu-24-04-beta-delayed) from the original on 8 April 2024. Retrieved 10 April 2024.
25. ^ [***a***](#cite_ref-Rudra2025_27-0) [***b***](#cite_ref-Rudra2025_27-1) Rudra, Sourav (14 August 2025). ["Security Researchers Find XZ Utils Backdoored Debian Images on Docker Hub"](https://news.itsfoss.com/xz-utils-backdoored-debian-images/). *news.itsfoss.com*. Retrieved 14 August 2025.
26. ^ [***a***](#cite_ref-githubdockerissue_28-0) [***b***](#cite_ref-githubdockerissue_28-1) Haruyama, Takahiro (6 August 2025). ["Docker Hub Debian image contains CVE-2024-3094 backdoor"](https://github.com/debuerreotype/docker-debian-artifacts/issues/246). *github.com*. Retrieved 14 August 2025.
27. **[^](#cite_ref-29)** ["Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images"](https://www.binarly.io/blog/persistent-risk-xz-utils-backdoor-still-lurking-in-docker-images). *binarly.io*. 12 August 2025. Retrieved 14 August 2025.
28. **[^](#cite_ref-30)** Arasaratnam, Omkhar; Bender Ginn, Robin (15 April 2024). ["Open Source Security (OpenSSF) and OpenJS Foundations Issue Alert for Social Engineering Takeovers of Open Source Projects"](https://openssf.org/blog/2024/04/15/open-source-security-openssf-and-openjs-foundations-issue-alert-for-social-engineering-takeovers-of-open-source-projects/). *OpenSSF*. Retrieved 1 January 2026.
29. **[^](#cite_ref-31)** Kovacs, Eduard (15 April 2024). ["Researchers stop 'credible takeover attempt' similar to XZ Utils backdoor incident"](https://therecord.media/researchers-stop-credible-takeover-xz-utils). *The Record*. Retrieved 1 January 2026.
30. **[^](#cite_ref-nytimes-interview_32-0)** Roose, Kevin (3 April 2024). ["Did One Guy Just Stop a Huge Cyberattack?"](https://www.nytimes.com/2024/04/03/technology/prevent-cyberattack-linux.html). *The New York Times*. [Archived](https://web.archive.org/web/20240404000115/https://www.nytimes.com/2024/04/03/technology/prevent-cyberattack-linux.html) from the original on 4 April 2024. Retrieved 4 April 2024.
31. **[^](#cite_ref-theverge_33-0)** Khalid, Amrita (2 April 2024). ["How one volunteer stopped a backdoor from exposing Linux systems worldwide"](https://www.theverge.com/2024/4/2/24119342/xz-utils-linux-backdoor-attempt). *The Verge*. [Archived](https://web.archive.org/web/20240404022427/https://www.theverge.com/2024/4/2/24119342/xz-utils-linux-backdoor-attempt) from the original on 4 April 2024. Retrieved 4 April 2024.

## External links

[[edit](/w/index.php?title=XZ_Utils_backdoor&action=edit&section=8)]

* [Official website](https://tukaani.org/xz-backdoor/)

[Portal](/wiki/Wikipedia:Contents/Portals):

* [Internet](/wiki/Portal:Internet)

| * [v](/wiki/Template:Hacking_in_the_2020s) * [t](/wiki/Template_talk:Hacking_in_the_2020s) * [e](/wiki/Special:EditPage/Template:Hacking_in_the_2020s)  Hacking in the 2020s |
| --- |
| ← [2010s](/wiki/Template:Hacking_in_the_2010s)  [Timeline](/wiki/List_of_security_hacking_incidents#2020s)  2030s → |
| Major incidents | |  |  | | --- | --- | | 2020 | * [BlueLeaks](/wiki/BlueLeaks) * [Twitter account hijacking](/wiki/2020_Twitter_account_hijacking) * [European Medicines Agency data breach](/wiki/European_Medicines_Agency_data_breach) * [Nintendo data leak](/wiki/Nintendo_data_leak) * [United States federal government data breach](/wiki/2020_United_States_federal_government_data_breach) * [EasyJet data breach](/wiki/EasyJet_data_breach) * [Vastaamo data breach](/wiki/Vastaamo_data_breach) | | 2021 | * [Microsoft Exchange Server breach](/wiki/2021_Microsoft_Exchange_Server_data_breach) * [Ivanti Pulse Connect Secure data breach](/wiki/Ivanti_Pulse_Connect_Secure_data_breach) * [Colonial Pipeline ransomware attack](/wiki/Colonial_Pipeline_ransomware_attack) * [Health Service Executive ransomware attack](/wiki/Health_Service_Executive_ransomware_attack) * [Waikato District Health Board ransomware attack](/wiki/Waikato_District_Health_Board_ransomware_attack) * [JBS S.A. ransomware attack](/wiki/JBS_S.A._ransomware_attack) * [Kaseya VSA ransomware attack](/wiki/Kaseya_VSA_ransomware_attack) * [Transnet ransomware attack](/wiki/Transnet_ransomware_attack) * [Epik data breach](/wiki/2021_Epik_data_breach) * [FBI email hack](/wiki/2021_FBI_email_hack) * [National Rifle Association ransomware attack](/wiki/2021_National_Rifle_Association_ransomware_attack) * [Banco de Oro hack](/wiki/2021_Banco_de_Oro_hack) * [Iranian fuel cyberattack](/wiki/2021_Iranian_fuel_cyberattack) | | 2022 | * [Ukraine cyberattacks](/wiki/2022_Ukraine_cyberattacks) * [Red Cross data breach](/wiki/Red_Cross_data_breach) * [Anonymous and the Russian invasion of Ukraine](/wiki/Anonymous_and_the_Russian_invasion_of_Ukraine) * [Viasat hack](/wiki/Viasat_hack) * [DDoS attacks on Romania](/wiki/2022_DDoS_attacks_on_Romania) * [Costa Rican ransomware attack](/wiki/2022_Costa_Rican_ransomware_attack) * [LastPass vault theft](/wiki/LastPass_2022_data_breach) * [Shanghai police database leak](/wiki/Shanghai_police_database_leak) * [*Grand Theft Auto VI* content leak](/wiki/Grand_Theft_Auto_VI#Leaks) | | 2023 | * [Munster Technological University ransomware attack](/wiki/Munster_Technological_University_ransomware_attack) * [Capita data breach](/wiki/2023_Capita_data_breach) * [Evide data breach](/wiki/Evide_data_breach) * [MOVEit data breach](/wiki/2023_MOVEit_data_breach) * [Insomniac Games data breach](/wiki/Insomniac_Games#December_2023_leak) * [Operation Triangulation cyberattack](/wiki/Operation_Triangulation) * [Polish railway cyberattack](/wiki/Polish_railway_cyberattack) * [British Library cyberattack](/wiki/British_Library_cyberattack) | | 2024 | * XZ Utils backdoor * [Kadokawa and Niconico](/wiki/2024_cyberattack_on_Kadokawa_and_Niconico) * [Change Healthcare ransomware attack](/wiki/2024_Change_Healthcare_ransomware_attack) * [Ukrainian cyberattacks against Russia](/wiki/2024_Ukrainian_cyberattacks_against_Russia) * [2024 WazirX hack](/wiki/2024_WazirX_hack) * [Trump campaign hack](/wiki/Iranian_interference_in_the_2024_United_States_elections) * [Fur Affinity domain hijacking](/wiki/Fur_Affinity) * [IRLeaks attack on Iranian banks](/wiki/IRLeaks_attack_on_Iranian_banks) * [Internet Archive data breach](/wiki/Internet_Archive#2024_Cyberattacks) * [i-Soon leak](/wiki/I-Soon_leak) * [2024 global telecommunications hack](/wiki/2024_global_telecommunications_hack) * [2024 National Public Data breach](/wiki/2024_National_Public_Data_breach) | | 2025 | * [Cyberattacks on Bank Sepah](/wiki/Cyberattacks_on_Bank_Sepah) * [2025 Paraguay ransomware attack](/wiki/2025_Paraguay_ransomware_attack) * [4chan hacking and data breach](/wiki/4chan#2020s) * [2025 St. Paul cyberattack](/wiki/2025_St._Paul_cyberattack) * [Jaguar Land Rover cyberattack](/wiki/Jaguar_Land_Rover_cyberattack) * [Collins Aerospace cyberattack](/wiki/Collins_Aerospace_cyberattack) * [2025 cyberattack on Polish power grid](/wiki/2025_cyberattack_on_Polish_power_grid) | | 2026 | * [ManageMyHealth data breach](/wiki/ManageMyHealth_data_breach) * [Neighbourly data breach](/wiki/Neighbourly#Data_breach) | |
| Groups | * [Anonymous](/wiki/Anonymous_(hacker_group))   + [associated events](/wiki/Timeline_of_events_associated_with_Anonymous) * [Anonymous Sudan](/wiki/Anonymous_Sudan) * [Berserk Bear](/wiki/Berserk_Bear) * [BlackCat](/wiki/BlackCat_(cyber_gang)) * [Clop](/wiki/Clop_(cyber_gang)) * [Cozy Bear](/wiki/Cozy_Bear) * [DarkMatter](/wiki/DarkMatter_Group) * [DarkSide](/wiki/DarkSide_(hacker_group)) * [Dark Storm Team](/wiki/Dark_Storm_Team) * [Dridex](/wiki/Dridex) * [Ghostwriter](/wiki/Ghostwriter_(hacker_group)) * [GnosticPlayers](/wiki/GnosticPlayers) * [Guacamaya](/wiki/Guacamaya_(hacktivist_group)) * [Hacktivist Nepal](/wiki/Hacktivist_Nepal) * [Hafnium](/wiki/Hafnium_(group)) * [Indian Cyber Force](/wiki/Indian_Cyber_Force) * [IT Army of Ukraine](/wiki/IT_Army_of_Ukraine) * [Killnet](/wiki/Killnet) * [Lapsus$](/wiki/Lapsus$) * [LightBasin](/wiki/LightBasin) * [LockBit](/wiki/LockBit) * [OceanLotus](/wiki/OceanLotus) * [REvil](/wiki/REvil) * [Rhysida](/wiki/Rhysida_(hacker_group)) * [Sandworm](/wiki/Sandworm_(hacker_group)) * [Sakura Samurai](/wiki/Sakura_Samurai_(group)) * [ShinyHunters](/wiki/ShinyHunters) * [SiegedSec](/wiki/SiegedSec) * [Vice Society](/wiki/Vice_Society) * [Wizard Spider](/wiki/Wizard_Spider) |
| [Individuals](/wiki/Hacker) | * [Graham Ivan Clark](/wiki/Graham_Ivan_Clark) * [maia arson crimew](/wiki/Maia_arson_crimew) * [IntelBroker](/wiki/IntelBroker) * [Kirtaner](/wiki/Aubrey_Cottle) |
| Major [vulnerabilities](/wiki/Vulnerability_(computing)) publicly [disclosed](/wiki/Full_disclosure_(computer_security)) | * [SMBGhost](/wiki/SMBGhost) (2020) * [Thunderspy](/wiki/Thunderspy) (2020) * [PrintNightmare](/wiki/PrintNightmare) (2021) * [FORCEDENTRY](/wiki/FORCEDENTRY) (2021) * [Log4Shell](/wiki/Log4Shell) (2021) * [Account pre-hijacking](/wiki/Account_pre-hijacking) (2022) * [Retbleed](/wiki/Retbleed) (2022) * [Downfall](/wiki/Downfall_(security_vulnerability)) (2023) * [LogoFAIL](/wiki/LogoFAIL) (2023) * [Reptar](/wiki/Reptar_(vulnerability)) (2023) * [Terrapin](/wiki/Terrapin_attack) (2023) * [GoFetch](/wiki/GoFetch) (2024) * [Sinkclose](/wiki/Sinkclose) (2024) |
| Malware | |  |  | | --- | --- | | 2020 | * [Adrozek](/wiki/Adrozek) * [CovidLock](/wiki/CovidLock) * [Drovorub](/wiki/Drovorub) | | 2021 | * [Predator](/wiki/Predator_(spyware)) | | 2022 | * [BlackLotus](/wiki/BlackLotus) * [Cyclops Blink](/wiki/Cyclops_Blink) * [Pipedream](/wiki/Pipedream_(toolkit)) | | 2023 | * [Akira](/wiki/Akira_(ransomware)) | | 2024 | * [Gayfemboy](/wiki/Gayfemboy) | | 2025 | * [BootKitty](/wiki/BootKitty) | |

Retrieved from "<https://en.wikipedia.org/w/index.php?title=XZ_Utils_backdoor&oldid=1334681698>"

[Categories](/wiki/Help:Category):

* [2024 in computing](/wiki/Category:2024_in_computing)
* [March 2024](/wiki/Category:March_2024)
* [Hacking in the 2020s](/wiki/Category:Hacking_in_the_2020s)
* [Computer security exploits](/wiki/Category:Computer_security_exploits)
* [Internet security](/wiki/Category:Internet_security)
* [Kleptography](/wiki/Category:Kleptography)
* [Social engineering (security)](/wiki/Category:Social_engineering_(security))
* [Trojan horses](/wiki/Category:Trojan_horses)

Hidden categories:

* [Articles with short description](/wiki/Category:Articles_with_short_description)
* [Short description is different from Wikidata](/wiki/Category:Short_description_is_different_from_Wikidata)
* [Use dmy dates from December 2025](/wiki/Category:Use_dmy_dates_from_December_2025)
* [Use Australian English from March 2024](/wiki/Category:Use_Australian_English_from_March_2024)
* [All Wikipedia articles written in Australian English](/wiki/Category:All_Wikipedia_articles_written_in_Australian_English)