How a Spy Infiltrated XZ Utils: The 849‑Day Supply‑Chain Attack on Billions of Linux Devices
An in‑depth investigation reveals how a lone maintainer of the ubiquitous XZ compression library was psychologically pressured, infiltrated by a fake contributor, and ultimately used to plant a CVE‑2024‑3094 backdoor that threatened billions of Linux servers worldwide.
