Patch Notes #274 — The Backdoor in the Compression Library
Dropping the usual format (the Heartbleed protocol, invoked for the fourth time in twelve years): the fortnight is xz. On March 29th, a Microsoft engineer named Andres Freund, investigating a half-second SSH latency regression and some odd valgrind noise on Debian test builds, pulled a thread that unraveled the most sophisticated supply-chain attack ever documented in open source: a backdoor in xz-utils (the compression library inside essentially every Linux distribution), inserted not by compromising code but by compromising trust itself. The multi-year mechanics, reconstructed publicly within days (the replication machine, forensic edition): a persona (“Jia Tan”) arrived in 2021 as a helpful contributor to a burnt-out solo maintainer (Lasse Collin, maintaining a universal dependency unpaid for fifteen years, the Log4j economics, the old sermon, unhealed); sockpuppet accounts pressured Collin about slow maintenance until he shared commit rights; “Jia Tan” then spent years earning release authority through legitimate work before landing the payload, hidden not in the readable source but in binary test files, activated only during packaged builds, targeting sshd via systemd’s libsystemd dependency chain, gated to specific distro-build environments to evade detection. It reached Debian and Fedora testing branches. It was weeks from the world’s production SSH servers. ...