‘xz utils’ Software Backdoor Uncovered in Years-Long Hacking Plot

dontcryforme

Executive Member
Joined
Sep 21, 2023
Messages
6,814
Reaction score
8,926

Xz-utils versions 5.6.0 and 5.6.1 were found to have the malicious programming added by “Jia Tan” (jiaT75) on GitHub. It got into the widely used Debian testing (pre-release) branch but not the stable branch. It also made it into the widely used OS X third-party package manager homebrew (although maintainers are optimistic it may not actually affect Apple machines). Red Hat also warned that some Fedora Linux 40 systems (as well as Rawhide, the pre-release for Fedora 41) may have gotten the malicious software. Jia Tan’s activities extended beyond just the xz-utils code, which people discovered on Friday.
 
Top
Sign up to the MyBroadband newsletter
X