# XZ Utils backdoor attempted supply chain compromise

Published: 2024-05-01 · Severity: routine · Sectors: technology, government-national, financial-services, healthcare, infrastructure, defense
Canonical: https://vorant.io/reports/134c97b4-8caf-5bd6-a5d2-24f418d3848e/xz-utils-backdoor-attempted-supply-chain-compromise

> A malicious maintainer nearly succeeded in inserting a remote-code-execution backdoor into XZ Utils, a critical Linux compression library, via social engineering; discovered before widespread deployment.

In March 2024, a sophisticated supply-chain attack targeted XZ Utils, an open-source data compression utility widely used in Linux distributions. The attacker, using the account JiaT75, spent years contributing to the project and systematically pressured the original maintainer into granting co-maintainer status. Once elevated, the attacker replaced the original maintainer's contact information on oss-fuzz, a vulnerability scanner, and introduced malicious code into versions 5.6.0 and 5.6.1 that would have enabled remote code execution on affected systems. The backdoor was discovered by a Microsoft engineer before it reached major Linux distributions; had it propagated, it would have compromised hundreds of millions of networked systems including cloud infrastructure worldwide.

The attack exploited open source's structural vulnerabilities: critical projects maintained by single, under-resourced individuals; reliance on trust within volunteer communities; and minimal vetting controls compared to proprietary software. This marks the first deliberate attempt to introduce malicious code into a widely-deployed OSS library, distinguishing it from historical accidental vulnerabilities like Heartbleed or Log4Shell. The attacker employed social engineering, cyber-bullying, and patience to achieve maintainer access, then concealed the malicious commits in the build system while disabling existing security checks.

Defenders should treat this as a wake-up call for supply-chain risk management. XZ Utils versions 5.6.0 and 5.6.1 were affected; users must downgrade to version 5.5.3 or earlier. The open-source model's transparency enabled detection before harm, but the incident demonstrates that critical infrastructure components now face state-level or sophisticated threat-actor targeting. Organizations must audit their dependencies, implement code-review and build-pipeline security, and support the maintainers of critical open-source projects they rely upon.

## Mentioned in this report

- Threat actors: JiaT75

Source reporting: https://www.atlanticcouncil.org/content-series/the-5x5/the-5x5-the-xz-backdoor-trust-and-open-source-software

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/134c97b4-8caf-5bd6-a5d2-24f418d3848e/xz-utils-backdoor-attempted-supply-chain-compromise.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
