Photo: Pok Rie / PexelsCVE-2024-3094: Two Years to Plant, One Benchmark to Find
The xz/liblzma backdoor, assigned CVE-2024-3094, was discovered in March 2024 by Andres Freund while investigating an SSH login slowdown on a Debian testing machine.
File 02 — The Plumbing
The supply chain nobody funded, the backdoors nobody caught in time, and the rules now being written.
Photo: Pok Rie / PexelsThe xz/liblzma backdoor, assigned CVE-2024-3094, was discovered in March 2024 by Andres Freund while investigating an SSH login slowdown on a Debian testing machine.
Photo: Alexis Caso / PexelsCVE-2021-44228, disclosed in December 2021, affected Apache Log4j 2 — a logging library maintained by a small volunteer team under the Apache Software Foundation and embedded in thousands of enterprise products.
Photo: Havvanur Akın / PexelsThe 2018 event-stream incident, in which a malicious maintainer injected a payload targeting a specific Bitcoin wallet, and the 2022 colors/faker protest, in which Marak Squires deliberately broke his own widely-used packages, are distinct failure modes in npm's dependency model.
Photo: Rafael Minguet Delgado / PexelsResearchers and security teams have documented recurring campaigns in which malicious packages with names differing by one character from popular libraries are published to npm and PyPI, collecting credentials or establishing persistence on developer machines.
Photo: Ron Lach / PexelsUS Executive Order 14028, signed in May 2021, required federal software vendors to produce Software Bills of Materials as a condition of sale — moving SBOMs from a NTIA working-group recommendation to a procurement requirement.
Photo: Lukas Blazek / PexelsSigstore, a Linux Foundation project, provides tooling for signing software artefacts and recording those signatures in a public, append-only transparency log — addressing the question of whether a release binary corresponds to the source it claims to come from.
Photo: Google DeepMind / PexelsThe Reproducible Builds project, operating since 2013 under the umbrella of several Linux distributions, works toward a state where any party can verify that a distributed binary was compiled from the stated source with the stated toolchain — closing the gap between a clean audit of source code and trust in what is actually shipped.