Latest
When a Client Thinks the Ghostwriter Used AIThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe One-Hour Call Before I Quote Your BookThe Work You Would Never Have StartedWhen Your Own Memoir Sounds Like BraggingMonthly or Milestone: How Ghostwriting Gets BilledWhat It Costs to Fix an AI-Written ManuscriptThe Quotation Marks That Get Authors SuedThe Hugging Face AI Agent Attack: An Operations ReadingBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreThe Web Got Fenced: What AI Search Costs Small SitesBlack Tuesday: The Web Ring War Nobody Outside It NoticedWhat the AI Visibility Industry Sells, and What the Evidence SaysBlack Tuesday: The Original ring-master.net Page, 2000Behind the Book: Peacekeeper, The Dissolution WarsBehind the Book: Real World SurvivalBehind the Book: Publish Your BookBehind the Book: ReincarnationBehind the Book: Sell Your BooksBehind the Book: Selling on eBay
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

The XZ Backdoor: Two Years of Patience, Caught by Luck

This entry is part 12 of 13 in the series Nothing Is Isolated
TL;DR: In 2024, the world came within days of a disaster it never saw coming. Someone had spent roughly two years posing as a helpful volunteer on a small, unglamorous piece of software that quietly runs on much of the internet. They earned the trust of the exhausted lone maintainer, were handed the keys, and slipped in a hidden backdoor that would have let them break into countless computers worldwide. It was caught by one engineer who noticed his login was running half a second slow. This is the twelfth article in a series on attacks that beat isolation, and it is the one where the attacker didn’t break the trust. They became it.
Series Navigation  (13 parts)

Everything the modern world runs on is built, in part, out of small pieces of free software written and maintained by volunteers. Not the big famous programs. The plumbing. The little utilities that compress a file, handle a connection, parse a date, buried so deep in the machinery that almost nobody thinks about them, running on servers and phones and devices in numbers no one can count. Much of this critical plumbing is maintained by one or two unpaid people in their spare time.

In 2024, an attacker went hunting in exactly that blind spot, and the story of what they did and how close they came should frighten anyone who depends on a computer. That means everyone.

What did the XZ backdoor let attackers do?

XZ Utils is one of those invisible pieces of plumbing. It’s a compression tool, software that squeezes files down to a smaller size, and it is so standard that it ends up installed, directly or through other programs, on a huge share of the computers running Linux, the operating system that powers most of the servers on the internet. You have never heard of it, and you almost certainly rely on it every day.

In early 2024, a hidden backdoor was discovered inside recent versions of XZ Utils. It was built so that an attacker holding a specific secret key could reach through the compression library into a common remote-login program and run their own commands on the machine, silently, bypassing the normal password checks. In plain terms: whoever planted it would have been able to break into an enormous number of computers around the world, at will, and nobody would have known how.

Security professionals rate vulnerabilities on a scale up to ten. This one was rated a ten, the maximum, and the rating almost undersells it. This wasn’t a flaw somebody found in existing software. It was a weapon someone deliberately built into the software, wearing the disguise of a routine improvement, and it was days from spreading into the stable versions that the whole world installs.

How do you plant a backdoor in software the whole world uses?

You don’t break in. You get hired, in effect, by being helpful. That move sets XZ apart from everything else in this series.

XZ Utils, like so much critical open-source software, was maintained largely by one person, a volunteer who had kept it running for years and, by his own accounts, was stretched thin and dealing with his own life.

In 2021, an account under the name “Jia Tan” appeared and began contributing to the project. Not maliciously, at first. Helpfully. Fixing things, submitting improvements, doing the tedious work that an overstretched maintainer is grateful for. Over roughly two years, this contributor made hundreds of contributions and slowly, patiently, built a reputation as a trusted, valuable member of the project.

Then came the pressure. Alongside the helpful work, other accounts appeared in the project’s discussions, complaining that the software wasn’t being updated fast enough, that the lone maintainer wasn’t keeping up, that the project needed someone more active in charge.

These accounts, widely believed to be part of the same operation, sockpuppets working the same con, pushed on exactly the sore spot of a tired volunteer: you’re not doing enough, and here is someone who is. The campaign worked. The maintainer, worn down and looking for help, gave Jia Tan expanded control over the project.

With the keys in hand, the attacker moved carefully. The malicious code was not dropped in plainly where anyone reviewing the project’s public source would see it. It was hidden in the packaged release files, the compiled bundles most systems install from, tucked into build scripts and disguised test files in a way designed to survive a normal review.

The trap was set, built into official releases, signed and shipped as a legitimate update from a trusted project, and it began making its way toward the stable versions that every major Linux system would soon adopt.

How did one engineer stumble onto the XZ backdoor?

By accident. By one person noticing that something was a little slow.

A software engineer named Andres Freund, who worked at Microsoft, was doing unrelated performance testing when he noticed that logging into a machine over the network was taking about half a second longer than it should. Half a second. Most people would never notice, and of the few who did, almost none would chase it.

Freund chased it. He dug into why the login was slow, found that a compression library was eating an odd amount of processor time, kept pulling the thread, and uncovered the backdoor hidden inside XZ Utils. He reported it publicly at the end of March 2024, and the security world’s weekend erupted.

Sit with how thin that margin was. The most sophisticated software supply chain attack anyone had seen, years in the making, aimed at much of the internet’s infrastructure, was caught because one careful engineer was bothered by a half-second delay and had the curiosity and the skill to run it down.

Had he shrugged, or been busy that week, the backdoored versions would have flowed into the stable releases and onto machines worldwide, and we would be telling a very different story, if we knew to tell it at all. There was no system that caught this. There was a person, and a coincidence.

Why is the XZ backdoor the most unsettling attack in this series?

Because it inverts the pattern of every other article here, and the inversion is worse.

In the pager attack, Israel built a company to become a trusted supplier. In Crypto AG, intelligence agencies bought a company to control a trusted product. Those took money, infrastructure, a nation behind them. The XZ attack achieved the same thing, trusted-supplier access to a critical piece of the world’s software, with almost none of that. It took one persistent person, a couple of fake accounts, and two years of patience. The barrier to becoming trusted was not a billion dollars. It was time and social pressure applied to a tired volunteer.

That should change how you think about the software running your life, because the same structural weakness is everywhere. A staggering amount of the code that runs the modern world is maintained by people who are unpaid, overworked, and largely unsupported, holding up infrastructure that trillion-dollar companies and governments depend on. Every one of those maintainers is a target for exactly the campaign that hit XZ: befriend, help, pressure, take over. We got lucky once, publicly. The honest question is how many times we haven’t.

The deepest link to the rest of this series, and to where it’s heading, is this. Throughout these articles, the attacker had to defeat the victim’s trust, cross the air gap, forge the certificate, poison the update.

XZ is the version where the attacker doesn’t defeat trust at all. They earn it, legitimately, through work indistinguishable from a good contributor’s, and then use it. There is no technical control that catches that, because at every step the attacker looked exactly like what a trustworthy participant looks like. The only defense is human judgment about who is being trusted with what. That is precisely the defense that does not scale, and precisely the one the final article in this series argues we are now handing to machines.

The last article steps back and asks what all twelve of these attacks, taken together, say about the AI systems being built right now, and about the trust we are placing in things whose behavior no one fully understands. For the wider view, the cybersecurity hub collects the rest of my work on security.

Frequently Asked Questions

What was the XZ Utils backdoor?
The XZ Utils backdoor, tracked as CVE-2024-3094, was malicious code deliberately hidden inside recent versions of XZ Utils, a compression tool installed on a large share of the world’s Linux systems. It let an attacker holding a secret key bypass login security and run their own commands remotely on affected machines. It was rated a maximum severity of ten out of ten and was discovered in March 2024.
How did the attacker get the XZ backdoor into the software?
Through a multi-year social engineering campaign, not a break-in. An account named “Jia Tan” spent about two years making genuine, helpful contributions to XZ Utils, building trust with the project’s overstretched volunteer maintainer. Other accounts, believed to be part of the same operation, pressured the maintainer to hand over more control. Once given it, the attacker hid the backdoor in the packaged release files where routine review would miss it.
How was the XZ backdoor discovered?
By chance. A Microsoft engineer named Andres Freund noticed that logging into a machine over the network was taking about half a second longer than normal. He investigated the slowdown, found a compression library consuming unusual processor time, and traced it to the hidden backdoor in XZ Utils. He reported it publicly at the end of March 2024, days before the backdoored versions would have spread widely.
How bad could the XZ backdoor have been?
Potentially catastrophic. XZ Utils runs on a huge share of internet servers, and the backdoor would have let whoever planted it break into an enormous number of machines worldwide at will, bypassing normal authentication. It was caught days before the affected versions were due to flow into the stable Linux releases that most systems install, so the widespread damage was narrowly avoided.
Who was Jia Tan?
“Jia Tan” was the online identity used to carry out the attack, an account that appeared in 2021 and contributed to XZ Utils for roughly two years before planting the backdoor. Whether it represents a real individual or a cover for a group, likely a well-resourced or state-linked operation given the patience and skill involved, has not been publicly established. The identity is widely believed to be a persona created for the attack.
Why is open-source software vulnerable to this kind of attack?
Because a great deal of critical open-source software is maintained by one or two unpaid volunteers holding up infrastructure that huge companies and governments depend on. An overstretched maintainer is grateful for help and open to pressure, the exact combination the XZ attacker exploited: befriend, contribute, apply pressure, and take over. The same structural weakness exists across much of the software the modern world runs on.
What makes the XZ backdoor different from other supply chain attacks?
Most supply chain attacks defeat trust by forging a certificate, poisoning an update, or breaking into a build system. The XZ attacker never defeated trust; they earned it, through work indistinguishable from that of a good contributor, and then abused it. No technical control catches that, because at every step the attacker looked exactly like a trustworthy participant. It also required only patience and social pressure, not a nation’s budget.

Continue the Series

1. The Morris Worm |
2. Stuxnet: The History |
3. Stuxnet: Crossing the Air Gap |
4. Stuxnet: The Aftermath |
5. The Pager Attack |
6. The Pager Supply Chain |
7. Crypto AG |
8. Agent.btz |
9. NotPetya |
10. SolarWinds |
11. The Target Breach |
12. The XZ Backdoor |
13. The Line to AI

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment