CVE-2024-3094: XZ Utils backdoor
Embedded Malicious Code: Is CVE-2024-3094 real, exploitable, or a false positive? Here's the community verdict.
signals
public sources
High severity and high exploitation probability. Prioritise remediation.
public exploits
links to sources — we don’t host codeUnverified proof-of-concept code has been published. It may or may not be functional — assess before relying on it.
baseline read
auto · not a community verdict
Likely real & worth prioritising
High base severity and a high real-world exploitation probability both point to a genuine, actively targeted issue.
Based on CVSS · FIRST EPSS
Confirm or dispute →CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
References
Published
Embed this verdict
[](https://www.truepositive.app/cve/CVE-2024-3094)<a href="https://www.truepositive.app/cve/CVE-2024-3094"><img src="https://www.truepositive.app/cve/CVE-2024-3094/badge.svg" alt="TruePositive verdict for CVE-2024-3094"></a>Live badge that updates automatically as the community verdict changes.
Community ground truth
Be the first practitioner to weigh in
So far this is only TruePositive's editorial baseline from public sources. Add your real-world verdict below — it becomes the signal the next person triaging this relies on.
🥇 The first 50 practitioners to contribute earn a Founding Contributor badge.
In your experience, is this finding real and exploitable?
awaiting field verdictsCurated baseline: TruePositive's read from public sources is Real, needs specific conditions — a starting point, not a community verdict.
No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.
Field notes & remediation
Verdicts are the quick signal. Notes are the evidence and fixes behind them.
- 0
This is a real backdoor, but for most companies the scanner alert does not apply. A malicious maintainer hid a backdoor in xz/liblzma versions 5.6.0 and 5.6.1. On some systems it hooks into sshd and lets one specific attacker (who holds a secret key) log in without a password. This is a targeted, government-level backdoor, not a mass attack.
Who was actually affected: only bleeding-edge or rolling distros around March 2024. That means Fedora 40 and Rawhide, Debian sid and testing, openSUSE Tumbleweed, Kali (for a short time), and Arch. Stable production systems like RHEL, Ubuntu LTS, Debian stable, and Amazon Linux shipped version 5.4.x and were never affected. It was found early (by Andres Freund) before it reached stable releases, so very few systems were hit.
So if your scanner flags xz 5.6.0 or 5.6.1, first check your distro. If it is a stable release, you are almost certainly not applicable. If it is rolling or beta, run
xz --version, run the public detection script against liblzma, and check whether your sshd is even linked to liblzma in the vulnerable way.Commonly flagged by: Trivy, Grype, Dependabot, OSV-Scanner.
- 0
Downgrade xz/liblzma to a safe 5.4.x version, or use your distro's fixed build (or 5.8+). If a system actually ran 5.6.0 or 5.6.1 with the vulnerable sshd link, treat it as possibly compromised. Rebuild it from clean sources, rotate SSH host keys and any secrets on that machine, and review access logs. If you were on a stable distro the whole time, you only need to confirm your version.
Add a field note or remediationoptional
Related CVEs
Same weakness: CWE-506 · Embedded Malicious Code.
- CVE-2025-30066HIGH 8.6KEVEPSS 72%
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
- CVE-2026-33634HIGH 8.8KEVEPSS 59%
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This incident is a continuation of the supply chain attack that began in late February 2026. Following the initial disclosure on March 1, credential rotation was performed but was not atomic (not all credentials were revoked simultaneously). The attacker could have use a valid token to exfiltrate newly rotated secrets during the rotation window (which lasted a few days). This could have allowed the attacker to retain access and execute the March 19 attack. Affected components include the `aquasecurity/trivy` Go / Container image version 0.69.4, the `aquasecurity/trivy-action` GitHub Action versions 0.0.1 – 0.34.2 (76/77), and the`aquasecurity/setup-trivy` GitHub Action versions 0.2.0 – 0.2.6, prior to the recreation of 0.2.6 with a safe commit. Known safe versions include versions 0.69.2 and 0.69.3 of the Trivy binary, version 0.35.0 of trivy-action, and version 0.2.6 of setup-trivy. Additionally, take other mitigations to ensure the safety of secrets. If there is any possibility that a compromised version ran in one's environment, all secrets accessible to affected pipelines must be treated as exposed and rotated immediately. Check whether one's organization pulled or executed Trivy v0.69.4 from any source. Remove any affected artifacts immediately. Review all workflows using `aquasecurity/trivy-action` or `aquasecurity/setup-trivy`. Those who referenced a version tag rather than a full commit SHA should check workflow run logs from March 19–20, 2026 for signs of compromise. Look for repositories named `tpcp-docs` in one's GitHub organization. The presence of such a repository may indicate that the fallback exfiltration mechanism was triggered and secrets were successfully stolen. Pin GitHub Actions to full, immutable commit SHA hashes, don't use mutable version tags.
- CVE-2024-4978HIGH 8.4KEVEPSS 27%
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vulnerability to execute of unauthorized PowerShell commands.
- CVE-2025-54313HIGH 7.5KEVEPSS 4%
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
- CVE-2026-45321CRIT 9.6KEVEPSS 2%
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The attacker chained three known vulnerability classes — a pull_request_target "Pwn Request" misconfiguration, GitHub Actions cache poisoning across the fork↔base trust boundary, and runtime memory extraction of the OIDC token from the Actions runner process — to publish credential-stealing malware under a trusted identity. Each affected package received exactly two malicious versions, published a few minutes apart.
- CVE-2025-30154HIGH 8.6KEVEPSS 2%
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.