A threat actor using the alias "Jia Tan" spent ~3 years building trust as a co-maintainer via social engineering and sock puppet accounts, then inserted a sophisticated backdoor into liblzma that modified OpenSSH's sshd to allow RCE via a specific private key (CVSS 10.0). Caught before reaching stable distributions when Microsoft engineer Andres Freund noticed a 500ms SSH performance regression. Had it deployed widely, every Linux SSH server could have been compromised.
Sources: Andres Freund disclosure · Red Hat response · Lasse Collin statement
SOURCE_SINGLE_CONTRIBUTOR + SOURCE_FEW_CONTRIBUTORS flagged extreme single-maintainer risk YEARS before attack
| Tool | Verdict | Details |
|---|---|---|
| OSS Risk Guard | Caught | SOURCE_SINGLE_CONTRIBUTOR + SOURCE_FEW_CONTRIBUTORS flagged extreme single-maintainer risk YEARS before attack |
| Endor Labs | Partial | Graph analysis might note contributor pattern change |
| Socket | Missed | Attack designed to evade package-level behavioral analysis |
| Snyk | Missed | No maintainer risk or malware detection |
| Sonatype (Nexus) | Missed | No maintainer risk detection |
| Black Duck | Missed | No maintainer risk detection |