backdoorsupply-chain-attacksocial-engineeringmalware

Wikipedia - XZ Utils Backdoor

Provides a seminal case study of a multi-year social engineering supply chain attack resulting in a hidden backdoor.

Summary

In February 2024, a highly sophisticated backdoor (CVE-2024-3094) was discovered in the liblzma library of the XZ Utils package (versions 5.6.0 and 5.6.1). An attacker using the pseudonym 'Jia Tan' spent three years (November 2021 to February 2024) building trust to gain co-maintainer status through social engineering. The malicious code, which targeted OpenSSH to enable remote code execution via the glibc IFUNC mechanism, was hidden within dormant compressed test files in the git repository. It was only activated during the build process by a modified `build-to-host.m4` script that was exclusively included in the release tarballs and completely absent from the source git repository.

Related Checks

PACKAGE_ACTIVE_MALWARE

A malicious backdoor providing remote code execution was introduced to the Linux build of the xz utility in versions 5.6.0 and 5.6.1.

Adverse Outcome

deploying compromised packages that grant attackers remote system access

Because

flagging packages with known active malware prevents the inclusion of heavily compromised, backdoored distributions in the software supply chain.

Gaps Analysis

Evidence

A modified version of build-to-host.m4 was included in the release tar file uploaded on GitHub, which extracts a script that performs the actual injection into liblzma. This modified m4 file was not present in the git repository

Blind Spot

Risk Guard does not diff the actual file contents of the published package artifact against the source repository to detect release-only code injections.

Actionable Capability

Risk Guard would be better if it cross-referenced and diffed the content of published packages against the source code repository to detect hidden build-time injections.

← Previous Next →