Social Engineering 2024 Incident #12 CVE-2024-3094

XZ Utils backdoor (CVE-2024-3094)

Estimated Financial Impact
$10-50M+ (potential hundreds of billions)
Blast Radius
CVSS 10.0; every Linux SSH server at risk

What Happened

A threat actor using the alias "Jia Tan" spent ~3 years building trust as a co-maintainer via social engineering and sock puppet accounts, then inserted a sophisticated backdoor into liblzma that modified OpenSSH's sshd to allow RCE via a specific private key (CVSS 10.0). Caught before reaching stable distributions when Microsoft engineer Andres Freund noticed a 500ms SSH performance regression. Had it deployed widely, every Linux SSH server could have been compromised.

Sources: Andres Freund disclosure · Red Hat response · Lasse Collin statement

✓

Risk Guard: Caught

SOURCE_SINGLE_CONTRIBUTOR + SOURCE_FEW_CONTRIBUTORS flagged extreme single-maintainer risk YEARS before attack

Risk Guard Check Codes That Flag This Incident

SOURCE_SINGLE_CONTRIBUTORSOURCE_FEW_CONTRIBUTORSPACKAGE_ACTIVE_MALWARE

How Every Tool Performed

1 Caught 1 Partial 4 Missed
Tool Verdict Details
OSS Risk Guard Caught SOURCE_SINGLE_CONTRIBUTOR + SOURCE_FEW_CONTRIBUTORS flagged extreme single-maintainer risk YEARS before attack
Endor Labs Partial Graph analysis might note contributor pattern change
Socket Missed Attack designed to evade package-level behavioral analysis
Snyk Missed No maintainer risk or malware detection
Sonatype (Nexus) Missed No maintainer risk detection
Black Duck Missed No maintainer risk detection
← strong_password gem aiocpa backdoor →