Automatically translated.View original post

Cyber Horror: The XZ Utils Backdoor Case (CVE-2024-

When the "back door" is secretly installed in the backbone of the Internet,

Imagine you locked a house with the strongest key in the world... but the "locksmith" you trust the most, sneaked a small secret hole in the back of the house without anyone knowing. This is the true story that almost destroyed the security system of the Internet world forever. - The XZ Utils Backdoor Case (CVE-2024-3094)

Lasse Collin: The Tired Single Caretaker

Before the incident, the XZ Utils program was overseen by Lasse Collin (Larhzu) for more than 15 years (since 2009) as a single volunteer. There was no compensation. He had to bear everything. Amid mental health problems and stress, he accumulated so much that activity in the project declined.

This is a weakness that "someone" sees and uses as a perfect infiltration channel.

Jia Tan (JiaT75): The Devil in the Saint Stain, and a 2-Year Plot

November 2021, a mysterious character named Jia Tan appeared. He did not hack the model in the movie, but used Social Engineering calmly and cruelly:

• Create trust - Send good code to help with small tasks.

• Create pressure - Use multiple sockpuppet accounts to send Lasse Collin pressure emails saying "Update is too slow" or "If you can't do it, give it to someone else."

• Seize Power - 2022, the weakest Lasse Collin, accepts Jia Tan as co-maintainer By 2023, Jia Tan controls almost all of the projects, and signs a backdoor-mounted version of tarball himself.

What Happened: Every Open Ghost Shackle (Technical Backdoor Mechanism)

The latter gained full-handed power, Jia Tan secretly embedded the backdoor into versions 5.6.0 (February 24, 2024) and 5.6.1 (March 9, 2024). This code is so complex that "looking with the naked eye can't see."

Details the techniques that make it the scariest:

• Backdoor is only hidden in release tarball (not in Git repository), thus passing the general developer review.

• Use 2 test files that are binary (bad-3-corrupt _ lzma2.xz and good-large _ compresed.lzma), which look like normal test files.

• The build-to-host.m4 file is modified (only available in tarball) to run multi-layer scripts: decode → crack file → insert shared object named liblzma _ la-crc64-fast.o

• Use the glibc IFUNC mechanism, replacing the RSA _ public _ decrypt function of OpenSSL.

• Relying on a "third-party patch" that makes sshd load libsystemd → load liblzma automatically

• Results: When a hacker sends a unique Ed448 key → a remote code execution (RCE) can be ordered before authentication without the system detecting it.

The 5.6.1 version also improves to hide the notch and add "modularity" (SentinelOne believes this is to prepare an additional backdoor implant in the future).

Turning point: A slowness of only 0.5 seconds that changed the world.

This almost became a global tragedy, if not for Andres Freund (Microsoft engineer).

While testing Debian Sid, he found:

• SSH login slows down 500 milliseconds (0.5 seconds)

• CPU usage slightly higher + Valgrind error

He dug so deep that he found several layers of foreign code and hurried to post oss-security on March 29, 2024, before this version was pushed into a big production distro for just a few days!

Current status of the project (2026)

• XZ Utils is edited immediately. Every big distro (Debian, Fedora, Red Hat, SUSE) withdraws version 5.6.x back to the old version.

• Lasse Collin back in charge of regular project GitHub open repo back

• Jia Tan is also a mystery. No one knows the real identity (expected to be a government-sponsored actor. Because of 2 + years of patience + high level of complexity).

• The "remains" of the backdoor were also found in some Debian Docker images on the Docker Hub (discovered by Binarly August 2025), but Debian left it as "historical artifacts" because it was a dev building, not a production.

Conclusion: The Expensive Lessons of the Open Source World

XZ Utils is the biggest reminder that "trust" is the most dangerous weakness in this day and age. The Internet world relies on volunteers like Lasse Collin who are overworked to allow the possibility of infiltration of bad-wishers like Jia Tan.

This event brought the Open Source community about a big change: increased governance, automated scanning, and better maintainer care.

But the question that still haunts everyone is...

Where is Jia Tan still hiding? And what is he planning next in other projects?

Main reference source (2026 update)

• Wikipedia: XZ Utils backdoor

• Wired: The Mystery of Jia Tan

• SentinelOne: XZ Utils Backdoor - Threat Actor Planned Further Vulnerabilities

• Binarly: Persistent risk in Docker images (2025)

• Ars Technica & The Verge

By the round ⚽️

# Trending

# Programming

# Lemon8

2 days agoEdited to

... Read moreหลังจากได้อ่านเรื่องราวของ XZ Utils Backdoor แล้ว ผมคิดว่านี่เป็นกรณีศึกษาที่สะท้อนความเสี่ยงสำคัญของซอฟต์แวร์ Open Source ที่หลายคนอาจมองข้ามไป ในฐานะนักพัฒนาและผู้ใช้งานโปรเจกต์ OSS ผมเองก็เคยเห็น maintainer หลายรายทำงานคนเดียวภายใต้แรงกดดันมหาศาล ซึ่งบางครั้งอาจไม่สามารถดูแลระบบได้ครบถ้วนตลอดเวลา การแทรกซึมของแฮกเกอร์ผ่าน Social Engineering อย่าง Jia Tan แสดงให้เห็นว่าเทคนิคโจมตีในโลกไซเบอร์ยุคนี้ไม่ได้ใช้แค่ฮาร์ดแวร์หรือโค้ดลับ แต่ยังพุ่งเป้าไปที่ความไว้ใจในชุมชนและความอ่อนแอของทีมงาน การที่ backdoor ถูกฝังใน release tarball ซึ่งนักพัฒนาไม่เห็นโค้ด แถมยังใช้ไฟล์ binary สำหรับการตรวจสอบปลอมเพื่อหลอกลวง ทำให้การตรวจจับยิ่งซับซ้อน ผมเองเคยประสบปัญหากับการจัดการซอฟต์แวร์ที่มี maintainer น้อยมาก จึงเข้าใจดีว่าความเสี่ยงนี้ไม่ใช่เรื่องไกลตัว เหตุการณ์นี้จึงเตือนให้เราตระหนักถึงความสำคัญของระบบ governance ที่เข้มแข็ง การตรวจสอบอัตโนมัติ และการสนับสนุนผู้ดูแลโปรเจกต์อย่างเหมาะสม ที่น่าสนใจคือความช้าเพียง 0.5 วินาทีที่พบโดย Andres Freund กลายเป็นจุดเปลี่ยนสำคัญที่หยุดยั้งโศกนาฏกรรมโลกไซเบอร์ครั้งใหญ่ เหตุการณ์นี้สอนให้รู้ว่าแม้รายละเอียดเล็กน้อยในระบบการทำงานก็สามารถบ่งบอกถึงภัยคุกคามร้ายแรงได้ สุดท้ายนี้ ผมคิดว่าความสงสัยและคำถามที่ว่าผู้โจมตี Jia Tan ยังแฝงตัวอยู่ที่ไหน และกำลังเคลื่อนไหวในโปรเจกต์อื่นหรือไม่ ควรเป็นแรงผลักดันให้วงการ Open Source และผู้ใช้ทั่วโลกเฝ้าระวังและร่วมมือกันเสริมแกร่งความปลอดภัยมากขึ้น เพราะเราทุกคนมีส่วนร่วมกับโครงสร้างพื้นฐานของโลกอินเทอร์เน็ตนี้โดยตรง

Related posts

I’m hurt fymm🤦🏾‍♂️💯 #explorepage✨ #ajstarxz #fineshyt #relatable #fypageシ
Aj💫

Aj💫

0 likes

#nails❤️ #nailinspo #nailsideas
🪼

🪼

645 likes

Which avatar is better
#fypシ #viral #robloxoutfit #robloxoutfitideas #viral The green bean I match with my friend and the others are just for fun
FondwolfEXZ

FondwolfEXZ

0 likes

I wanted a real project I could actually show, not just talk about. So I used Atoms ⚛️ Check it out here: https://tinyurl.com/3xzc8xbe It feels like having a whole AI team helping me: 🔍 they do the deep research first 🏁 then Race Mode builds different versions so I can compare 👥 I just pick
emilie.studygram

emilie.studygram

19 likes

Take me thru dea🤣🚗 #trending #xyzbca #relatable #comedy #ajstarxz
Aj💫

Aj💫

0 likes

Part 3 How I ACTUALLY Removed Netherite #toan #luigi #strengthsmp #travel #minecraft
KARDS KATCH UP

KARDS KATCH UP

0 likes

Outfit details link : https://liketk.it/4Jpxz
Nakiah

Nakiah

1071 likes

Noxz ‘Into U Baby (mashup)’ was begging for sax
Noxz ‘Into U Baby (mashup)’ was begging for sax #noxz #intoubaby #sax #music #tamia #rhianna
ChrisMitchellJazz

ChrisMitchellJazz

157 likes

ดีล Anker ราคาพิเศษ ช้อปผ่าน Otta รับแคชแบ็ก กดลิงก์หน้าโปรไฟล์!
#ของดี3C #Anker #แคชแบ็ก #ประหยัด #lazada Chiang Mai https://ottamediaactive.onelink.me/sxzm/h1f7zx63
Karry

Karry

0 likes

bangchan edition
I post funny pictures of them! (Lee know next) #skzfyp #skzbangchan #fyp #skz
Editor_xz

Editor_xz

36 likes

I’m amazed ✨ credits to @bee.editxz
#katseyeedit #katseye
👑𝓔𝓨𝓔𝓚𝓞𝓝 𝓜𝓐𝓝𝓞𝓝👑

👑𝓔𝓨𝓔𝓚𝓞𝓝 𝓜𝓐𝓝𝓞𝓝👑

141 likes

Whole time I’m the problem 😭🤣 #explorepage #relatable #follower #friendgroup #ajstarxz
Aj💫

Aj💫

0 likes

I might needa get the teacher #explorepage #homeboy #relatable #ajstarxz #fypシ゚viral
Aj💫

Aj💫

18 likes

A.J.Adams

A.J.Adams

0 likes

🫣😅 #danhausen #wweraw #wwetiktok #fyp #yxzcba
Ohheyitsmissa💋

Ohheyitsmissa💋

3 likes

Twin I gotta break it to you 🤦🏾‍♂️ #explorepage #backdoor #goofy #relatable #ajstarxz #slimey #4upageシ
Aj💫

Aj💫

0 likes

😽 #chitown #xzyabc
nita rose 🌛🌸🫐🐞🧚

nita rose 🌛🌸🫐🐞🧚

0 likes

#fyp #xyzcba #videogames #games
⠀ ⠀ ⠀ ⠀ ⠀ ⠀zexxzty

⠀ ⠀ ⠀ ⠀ ⠀ ⠀zexxzty

0 likes

#nails❤️ #beautiful nails 😍 #nailinspo
🪼

🪼

127 likes

Working 8 mfs jobs😐🗣️ #fypageシ #xyzbca #superbowl #pizza #ajstarxz
Aj💫

Aj💫

4 likes

All dreadheads ain’t evil luh baby🤦🏾‍♂️💯👀 #fypageシ #dreadhead #xyzbca #relatable #ajstarxz
Aj💫

Aj💫

7 likes

Know they hate too see me coming😭💯 #explorepage #ajstarxz #vibewithme #relatable #walmart
Aj💫

Aj💫

0 likes

Sbbgfntbtn😂🫣 #foryou #fendidarapper #xyzbca #ajstarxz #chicago
Aj💫

Aj💫

3 likes

Blueface Flirts With/ New Women🔗https://youtu.be/C34vkJVpDPg?si=Js_VzXzrutngWQT
Blueface Flirts With/ New Women🔗https://youtu.be/C34vkJVpDPg?si=Js_VzXzrutngWQTS 🔥CamsDIY https://youtube.com/@camsdiy?feature=shared 🔥IIC PODCAST https://youtube.com/@iicpodcastonline?si=bf1TU73c0Ke-wbqp #Blueface #JaidynAlexis #Nevaeh #StunnaGirl @camsdiy @iicpodcast
CamsDIY

CamsDIY

0 likes

Xzlove lab growth diamond
🛍Brand:xzlove 💰Price:2000 ⭐️Overall rating: /5:10 Item:18k #diamond #xzlove
XZ’LOVE

XZ’LOVE

5 likes

DONT CLICK THE SOUND
#cod #callofduty #kbm #goated #clip
FAYXZ PLAYS COD

FAYXZ PLAYS COD

2 likes

It ain’t Friday today Saturday”😭 #foryou #lilcam_ongo #xyzbca #yn #ajstarxz
Aj💫

Aj💫

1 like

Fatso needa finish Ts😐 #foryou #relatable #trending #backdoor #ajstarxz
Aj💫

Aj💫

8 likes

More AMBER GLOW at Dollar Tree!✨
Matching Wipes to this collection! Grab em while you can! #dollartreefinds #fyp #newitem
sweetsugatherapy

sweetsugatherapy

62 likes

Lowk just emptying out my drafts #xyzcba #fyp #marvelrivals #marvel
⠀ ⠀ ⠀ ⠀ ⠀ ⠀zexxzty

⠀ ⠀ ⠀ ⠀ ⠀ ⠀zexxzty

0 likes

soulxzzt died in the most funny ass way
#callofdutywarzone #funnymoments #fyp
BNTH fidget

BNTH fidget

1 like

Anyone else dealt with this? Seeing my pobrecito scratch like crazy breaks my heart. 💔 Any tips or consejos? #perrostiktok #perrijos #dogmom #doghealth #consejos
bnzxz96850

bnzxz96850

0 likes

Like what??? cc:mine scp:enhalxz #ni _ki #ENHYPEN #nishimurariki #kpop #fyp @k 🍓 @𝘫𝘢𝘴. ݁𝜗𝜚. ݁₊ @zaraa @elena🫧
jazzy☽༓・*˚⁺‧͙

jazzy☽༓・*˚⁺‧͙

4 likes

WHO WON THE GRAMMY’S?🧏🏾‍♂️👂🏾 #whoami_85 #vsp #fyp #zyxcba #xzyabc #editor #edit #videostar #videostar #billieeilish #grammys #stfu #billieeilishedits @Video Star Official @BILLIE EILISH @fushi :3 @𝓡𝓤𝓑𝓨 @st☆rz @𐌃𐌀ⵍᘐ𐌄𐌓𐌁𐌆𐌋𐌔 || @prodkaz @wiccanwv @JAY🫁
Whoamii

Whoamii

0 likes

See dats ai😭 #explorepage #fypシ゚viral #caughtin4k #ajstarxz #park
Aj💫

Aj💫

0 likes

คู่มือรับส่วนลดกับแคชแบ็ก ใครยังทำไม่เป็น ทักมาคุยส่วนตัวได้เลยน้า
#ของดี3C #Anker #Otta #แคชแบ็ก #ประหยัด Chiang Mai
Karry

Karry

0 likes

Xzlove lab growth diamond
#xzlove #labgrowndiamond
XZ’LOVE

XZ’LOVE

3 likes

#explorepage #jayvenfunny #ajstarxz #viral #relatable
Aj💫

Aj💫

0 likes

ᑎᑌᖇᐯI . go to tiktok to see more videos bmnxz.i
#hair growth oil🫶🏾 #Hair #oil #fyp #entrepreneur
Bleu

Bleu

65 likes

Better see you wrapped under that tree 💕🤷🏾‍♂️ #explorepage #trending #christmaslist #relatable #ajstarxz
Aj💫

Aj💫

0 likes

Tricia

Tricia

80 likes

#4upage #wockst★rz🦇 #real #goodpeople #ajstarxz
Aj💫

Aj💫

0 likes

We can run the 1s anytimeee😂 #foryou #xyzbca #chicagotiktok #ajstarxz #relatable
Aj💫

Aj💫

3 likes

SHEIN codes for your next order (: - - #shein #sheincode #sheinhaul #sheindiscount #sheincodes Key Words: SHEIN haul , SHEIN clothes , SHEIN , SHEIN codes, SHEIN codes now, SHEIN coupon , SHEIN discount ( As a SHEIN Campus Ambassador, I earn from qualifying purchases.)
Atilana <3

Atilana <3

0 likes

Five and Below Finds ☆
MusicHølic

MusicHølic

1545 likes

MISS DIOR PARFUM 2024 🎀
A new added to my collection. I love this perfume! Beautiful light floral scent, still smells good without being overpowering. It smells the perfect mix between floral and classy.🎀 #diorperfume #miss dior #designerperfume #Lemon8Diary #momlife #momlifestyle
Eunicexz

Eunicexz

20 likes

Last day for DxZ
@Malachi Barton @Freya Skye
Odie0216 (Aligned)

Odie0216 (Aligned)

56 likes

Ima know if it do😐💯 #4upageシ #relationship #relatable #fypシ #ajstarxz
Aj💫

Aj💫

1 like

Xzlove lab growth diamond
#xzlove #labgrowndiamond
XZ’LOVE

XZ’LOVE

2 likes

See more