Messing with open source software

Arjen

It's turtles all the way down
Senior Member
Joined
6 November 2010
Messages
4,355
Reaction score
3,448
Somebody is messing with open source software:

Posted on Monday, April 1, 2024.​

Updated Wednesday, April 3, 2024.​


Over a period of over two years, an attacker using the name “Jia Tan”worked as a diligent, effective contributor to the xz compression library,eventually being granted commit access and maintainership.Using that access, they installed a very subtle, carefully hidden backdoor into liblzma,a part of xz that also happens to be a dependency of OpenSSH sshdon Debian, Ubuntu, and Fedora, and other systemd-based Linux systems that patched sshd to link libsystemd.(Note that this does not include systems like Arch Linux, Gentoo, and NixOS, which do not patch sshd.)That backdoor watches for the attacker sending hidden commands at the start of an SSH session,giving the attacker the ability to run an arbitrary command on the target system without logging in:unauthenticated, targeted remote code execution.

The attack was publicly disclosed on March 29, 2024 andappears to be the first serious known supply chain attack on widely used open source software.It marks a watershed moment in open source supply chain security, for better or worse.
Apparently, the issue affected 'unstable' linux-versions.
More at the link.
 
Last edited:
Yes, the people involved seemed to spend at least a year making valid contributions to the code before adding the malicious code. Nation state level planning.

Ultimately this attempt failed because the malicious code was discovered before any mainstream Linux distributions likely to be in use in target institutions incorporated the change, but the potential impact was insanely wide.
 
Yep - some key open source projects might only have one core contributor. If they pack it in and hand over to someone else, what validation do they do that the new contributor is not a nation state paid threat?
 
systemd working as intended, just the "wrong" country exploiting it....
 
Confusingly, "Jia Tan" might be from darkest Peru.
1000006659.jpg
 

Similar threads

Back
Top Bottom