XZ Utils liblzma Upstream Linux Supply Chain Backdoor (CVE-2024-3094)
Key Facts
- Legal Status: INVESTIGATION in Cybersecurity and Infrastructure Security Agency Alert.
- Primary Target Sector: Open Source Software & Linux Ecosystem.
- Documented Financial Loss: $150.0 million.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2024-3094) combined with targeted spearphishing and stolen remote access credentials.
Operational & Financial Fallout
Global developer triage, emergency distribution downgrades, and open-source maintainer security reviews. Impacted Open Source Software & Linux Ecosystem infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2024-3094) combined with targeted spearphishing and stolen remote access credentials.
Adversary Kill Chain Flow
2 Documented PhasesOperatives secured access to victim infrastructure within the Open Source Software & Linux Ecosystem sector.
Sophisticated multi-year social engineering and software supply chain operation where persona Jia Tan gained co-maintainer status on the foundational open-source xz compression project, embedding a multi-stage obfuscated backdoor into liblzma tarballs that hijacked OpenSSH sshd authentication to enable unauthorized pre-auth remote code execution.
Global developer triage, emergency distribution downgrades, and open-source maintainer security reviews. Impacted Open Source Software & Linux Ecosystem infrastructure and associated victim operations.
Procedural & Incident Timeline
Jia Tan pushes commits containing backdoored release tarballs xz-5.6.0 and xz-5.6.1.
PostgreSQL developer Andres Freund discovers CPU micro-benchmarking latency anomalies in sshd, exposing the backdoor.
CISA issues emergency advisory urging immediate downgrade of Linux packages.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1195.001 | "The attacker inserted malicious M4 macros into build test files during tarball release generation, modifying the build pipeline to inject binary code into liblzma.so." | Openwall Disclosure by Andres Freund | reviewed | |
| T1574.006 | "The backdoor hooked the OpenSSH RSA_public_decrypt function via ELF indirect functions (IFUNC) before main execution, allowing custom signed payloads to bypass authentication." | CISA Alert AL24-089A | reviewed |