Federal Criminal Record investigation
XZ Utils liblzma Upstream Linux Supply Chain Backdoor (CVE-2024-3094)

Sophisticated multi-year social engineering and software supply chain operation where persona Jia Tan gained co-maintainer status on the foundational open-source xz compression project, embedding a multi-stage obfuscated backdoor into liblzma tarballs that hijacked OpenSSH sshd authentication to enable unauthorized pre-auth remote code execution.

Loss Amount $150M
Techniques 2 Mapped
Threat Actor Individual