The Attack: A Two-Year Operation
Beginning in 2021, a persona named "Jia Tan" began contributing to the XZ-utils project — a compression utility present in virtually every Linux distribution. Over two years, Jia Tan built a credible reputation as a helpful, skilled contributor. They submitted numerous legitimate bug fixes, improvements, and optimizations. They earned the trust of the project's long-time maintainer, who was dealing with personal burnout, and were eventually granted maintainer access.
With maintainer access, Jia Tan introduced a carefully crafted backdoor in XZ-utils versions 5.6.0 and 5.6.1. The malicious code was hidden in binary test files and only activated during the build process under specific conditions — targeting systemd-based Linux systems where XZ-utils was linked against glibc and where the build environment matched the attacker's target. The backdoor subverted the RSA key authentication in OpenSSH, enabling the attacker to authenticate to any affected system using their private key.
How Close It Came to Succeeding
At the time of discovery, XZ-utils 5.6.0 and 5.6.1 had already been incorporated into the testing and unstable branches of Fedora 40, Fedora Rawhide, Debian testing, and openSUSE Tumbleweed. Had the release cycle continued normally for a few more months, the backdoor would have appeared in stable Debian and Fedora releases — installed on millions of servers worldwide. The discovery was described by security researchers as "incredibly lucky."
What This Attack Reveals About Supply Chain Risk
The XZ attack demonstrates several supply chain threat vectors that traditional security approaches cannot detect: a malicious actor operating as a legitimate, trusted contributor over an extended time horizon; backdoor code that is only activated under specific conditions, evading automated testing; and an attack vector through binary test files rather than source code, which many security scanners do not analyze.
Implications for SBOM and SCA Programs
The XZ attack does not invalidate SBOM and SCA programs — it clarifies what they can and cannot do. SBOMs and vulnerability scanners are highly effective at detecting known vulnerabilities in known components. They are not designed to detect novel backdoors in legitimate-appearing contributions. The XZ attack's CVE (CVE-2024-3094) was quickly added to vulnerability databases, and organizations with SBOM monitoring were able to identify affected deployments almost immediately after the public disclosure. The post-discovery response was significantly faster for organizations with mature SBOM programs.
Monitor Your Supply Chain in Real Time with Fossity
Fossity — The XZ-utils backdoor became CVE-2024-3094 within hours of public disclosure. Organizations using Fossity for continuous SBOM monitoring received immediate alerts about affected components. When the next supply chain incident hits, Fossity ensures you know your exposure before attackers can exploit it.
Visit Fossity.com →