Technical case study of the XZ Utils backdoor (CVE-2024-3094), covering supply-chain trust abuse, malicious release artifacts, build-stage injection, sshd dependency abuse, detection engineering and Red Team lessons.
When maintainer trust became the attack path.
CASE-002 reconstructs the XZ Utils / liblzma backdoor disclosed on 29 March 2024 as CVE-2024-3094.
The report follows the operation from long-term maintainer trust and release authority, through the mismatch between reviewed Git source and distributed release tarballs, into build-time payload extraction, liblzma modification, the transitive dependency path into sshd, GNU IFUNC / dynamic-linker abuse, and the operator-only pre-authentication trigger.
The focus is not merely what the backdoor did, but how multiple legitimate trust relationships were converted into an execution path.
Core lesson: source review is not release verification, and a signed upstream artifact is only as trustworthy as the human and build process that produced it.
Open the report in the repository →
Download the v1.0.0 release asset →
Integrity check: report/SHA256SUMS.txt
Contributor trust
↓
Maintainer / release authority
↓
Opaque test artifacts
↓
Tarball-specific build logic
↓
Build-time malicious object extraction
↓
Payload linked into liblzma
↓
Trusted distro package build
↓
Transitive load into sshd
↓
IFUNC / loader-time symbol redirection
↓
Operator-only cryptographic SSH trigger
↓
Pre-authentication bypass / command capability
| Finding | Why it matters |
|---|---|
| Maintainer trust was part of the exploit chain | The attacker operated from inside a legitimate project role rather than simply stealing a package account at the final stage. |
| Git source and release tarballs were not security-equivalent | Release-only generated build logic introduced a path that ordinary Git review did not expose. |
| Opaque test data became executable build input | Crafted .xz / .lzma fixtures carried hidden stages that were recovered during compilation. |
| The payload relied on a transitive dependency path | OpenSSH itself was not backdoored; liblzma reached selected sshd builds indirectly through distribution-specific systemd integration. |
| Runtime activation was deliberately narrow | Platform, build, process, environment and cryptographic gates reduced accidental exposure and analysis. |
| The discovery came from anomaly investigation | CPU, latency and Valgrind irregularities exposed a supply-chain compromise that static trust signals had accepted. |
sshd → libsystemd → liblzma dependency pathThis case study intentionally goes beyond incident summary.
The report maps six conversions of trust:
contributor → maintainer → release artifact → distro package → runtime library → SSH control path
At every conversion point, it identifies the attacker's leverage and a defensive choke point.
The analysis turns the incident into testable hypotheses around:
The emulation section focuses on safe trust-path testing, such as benign tarball/source mismatches and dependency-path validation, without requiring a functioning SSH authentication backdoor.
The PDF is generated from version-controlled HTML/CSS by .github/workflows/publish-report.yml.
The workflow renders the body and dedicated cover separately, merges them, calculates SHA-256, commits the generated PDF and publishes the release asset. This keeps the publication itself aligned with the central lesson of the case: the path from source to artifact should be observable and reproducible.
Primary evidence is prioritized over retrospective commentary. The report separates confirmed technical behavior, project records, distribution exposure, later reverse engineering and analytical conclusions.
See docs/METHODOLOGY.md and docs/REFERENCES.md.
.
├── .github/workflows/
│ └── publish-report.yml
├── assets/
│ └── cover-mobile-safe.svg
├── docs/
│ ├── METHODOLOGY.md
│ └── REFERENCES.md
├── report/
│ ├── cover.html
│ ├── source.html
│ ├── XZ_Utils_Backdoor_Case_Study_Michel-DV.pdf
│ └── SHA256SUMS.txt
├── CHANGELOG.md
├── CITATION.cff
├── DISCLAIMER.md
├── RELEASE_NOTES.md
├── LICENSE
└── README.md