Corpus graph preview Actor to Incident
Supply Chain Graph Pan, zoom, and select actor, campaign, and incident tiers.

Supply Chain graph is loading. Keyboard controls become available after graph initialization.

Supply Chain Incident

Focused Graph View

The persistent graph is framed to this incident while the canonical page heading and details continue below.

262 nodes 451 edges Cold links hydrate here

Supply Chain Incident

XZ Utils backdoor attempt

A backdoor was inserted into upstream XZ Utils release tarballs, affecting some downstream Linux distribution packaging before broad removal.

ConfidenceHigh
Evidence LevelPrimary
Attack StageSource Compromise
Source Artifact DivergenceYes
Attribution ConfidenceSuspected

Executive Summary

Timeline

  1. Backdoored release artifacts precede public disclosure

    The corpus records first observed activity before the Openwall disclosure and models the affected path as upstream source release distribution.

  2. Openwall disclosure documents the backdoor

    The Openwall oss-security post is the primary reference for the xz/liblzma backdoor record.

Attack Chain

  1. Upstream project influence

    The corpus records Jia Tan as a maintainer entity connected to the upstream xz project and this incident.

  2. Source release artifact compromise

    The compromised path is modeled through upstream source release tarballs, not a live package feed or graph database.

  3. Downstream Linux packaging exposure

    The affected ecosystems include Linux and source-release distribution because downstream packaging consumed the upstream release artifacts.

Affected Ecosystem

Defensive Lessons

Detection Notes

Open Questions

Affected Packages

No structured records.

Affected Releases

No structured records.

Repositories

Organizations

Maintainers

Threat Actors

  • UNC-XZ-UTILS

Campaigns

No structured records.

Build Systems

No structured records.

Distribution Channels

  • Upstream source release tarball

Compromised Accounts

No structured records.

Connected Entities

Attribution Evidence

References