How the Access Was Built

The account registered on GitHub as 'Jia Tan' first appeared in the xz Utils issue tracker in late 2021. The project was maintained by Lasse Collin, a solo volunteer, and the account initially behaved as a model contributor — submitting thoughtful patches, responding constructively to feedback, and helping manage a backlog that Collin had little capacity to clear alone. Over the following months the account accumulated enough trust to be granted commit rights to the repository. That arc — sustained, technically credible participation leading to elevated privilege — is now the clearest documented example of a long-duration social-engineering campaign targeting a foundational open-source project.

Pressure accompanied the technical contributions. A second account, operating as 'Jigar Kumar', appeared on the mailing list and in issue threads, criticising Collin for slow development and urging that Jia Tan be given more responsibility. The relationship between the two accounts has never been publicly attributed to separate individuals; the pattern functioned as a coordination mechanism designed to accelerate the transfer of trust. Collin, who had publicly described struggling with the pressures of maintaining a critical piece of infrastructure alone, found the situation difficult to resist. By early 2024, Jia Tan held enough control over the project to make commits to the release archive without those changes being immediately visible in the upstream Git repository.

A licence file — its SPDX header and copyright notice clearly visible — displayed in a terminal window on a large monitor, shot at an angle that shows both the text and the room behind it
PLATE 02The header block is where the terms live; everything downstream reads it as the contract.Photo: Pixabay / Pexels

The Payload and Its Discovery

The backdoor itself was not inserted into the readable C source. It was embedded inside test files — binary blobs included in the distributed source tarball — and activated through a complex build-time script that modified the compiled liblzma library. The modified library was then linked into systemd on Linux distributions that use it, and systemd is linked into OpenSSH's server process on several major distributions. The effect, once triggered under the right conditions, was to intercept and manipulate RSA key authentication in the SSH daemon, potentially allowing a remote attacker in possession of a specific private key to authenticate to any system running the compromised library without valid credentials.

An adult developer's desk with two monitors showing a GitHub pull-request diff and a dependency graph, a coffee cup in the foreground, shot in available office light
PLATE 03Review capacity, not code, is the scarce resource in most of these projects.
Photo: Lee Campbell / Pexels

Andres Freund, a software engineer at Microsoft working on PostgreSQL, was not looking for a backdoor. He was investigating why SSH logins on a Debian Sid (unstable) machine were consuming several hundred milliseconds more CPU time than expected, and why Valgrind — a memory analysis tool — was producing unexpected error output. Freund's methodical investigation eventually pointed at the version of xz Utils present on the system. On 29 March 2024 he posted his findings to the oss-security mailing list, describing the mechanism he had traced and making the payload public. The post triggered immediate triage across the Linux distribution ecosystem.

The CVE record, CVE-2024-3094, was assigned the same day. CVSS scored it 10.0 — the maximum — given that successful exploitation would yield unauthenticated remote access to a root-owned process on any affected system at internet scale. The affected versions were xz Utils 5.6.0 and 5.6.1, released in February and March 2024 respectively. Debian Sid, Fedora Rawhide, and Fedora 40 beta had already shipped those versions; stable releases of major distributions had not, which materially limited the blast radius.

  1. CHRONOLOGYAS RECORDED
  2. Late 2021Jia Tan account begins contributing to xz Utils
  3. February 2024xz Utils 5.6.0 released, containing the backdoor
  4. March 2024xz Utils 5.6.1 released; Debian Sid, Fedora Rawhide ship it
  5. 29 March 2024Andres Freund posts to oss-security; CVE-2024-3094 assigned
  6. CVSS score10.0 (maximum severity)

What the Incident Revealed

The xz case compressed several overlapping structural problems into one timeline. The first is the dependency model itself: xz/liblzma is embedded in operating systems, build toolchains, and compression pipelines across the Linux ecosystem, yet for most of its life it had a single active maintainer with no institutional backing. The second is the gap between source code and release artefact. The payload did not live in the Git history Collin managed — it lived in the binary test files inside the tarball distributed to distributions that pull from release archives rather than from Git. That gap is precisely the problem that reproducible builds and provenance attestation tooling exist to close, and the xz case became the sharpest possible argument for both.

The third problem is the social surface. Open-source governance assumes good faith from contributors who demonstrate sustained, competent participation. There is no mechanism in most projects — and there was none in xz — to verify that a contributor account corresponds to a real, accountable individual, or to detect coordinated pressure campaigns operating across multiple pseudonymous identities. The Jia Tan account was never publicly attributed to a named person or state actor by any government agency in the period following disclosure; analyses published by security researchers identified code style patterns and time-zone artefacts in the commit metadata, but attribution remained contested and unconfirmed.

An old shareware CD-ROM sleeve — a 1990s compilation disc — shot flat on a light surface as a period object, the printed cover art and 'shareware' label clearly visible
PLATE 04The channel that ran on an honour system, before a store sat in the middle of every install.
Photo: Arturo Añez. / Pexels

The funding dimension ran underneath all of it. Lasse Collin maintained xz Utils without corporate employment or formal grant support. The Sovereign Tech Fund, backed by the German Federal Ministry for Economic Affairs and Climate Action, had begun investing in critical open-source infrastructure in the years prior, but xz was not among its funded projects at the time of the incident. The pattern — a widely deployed library sustained by one person working effectively without pay — is not unique to xz. Daniel Stenberg has documented an equivalent structural position for curl over two and a half decades. Denis Pushkarev published a detailed accounting of the same dynamic for core-js in 2023. The xz backdoor made the argument visceral in a way that download statistics and CVE counts had not: the funding gap is also an attack surface.

The immediate response — distribution rollbacks, binary diffing of the compromised tarballs, public post-mortems, CISA advisories — was fast and effective given how early the versions were in their distribution cycle. What it could not do was answer the question of how many other repositories in analogous positions exist, maintained by individuals under similar pressure, with similar gaps between their source trees and their release artefacts. Freund found this one because he followed an anomalous benchmark. The next one may not surface that way.