Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/Malicious Packages/xz / liblzma
Supply-Chain Attack

xz / liblzma

ShareXLinkedInRedditHN

A hidden backdoor was planted over years by a trusted maintainer ('Jia Tan') in the xz-utils compression library, targeting OpenSSH sshd via liblzma to allow remote code execution.

Attack type
Backdoor
Ecosystem
Linux
Year
2024
Severity
Critical

Impact

Nearly shipped in mainstream Linux distributions; caught days before wide release. One of the most sophisticated OSS supply-chain attacks ever found.

What is backdoor?

Hidden code was planted to grant the attacker covert access or remote code execution.

Advisory IDs: CVE-2024-3094
Read the advisory / write-up

Protect your supply chain

Attacks like this are why dependency provenance matters. Scan your manifests against the Gold database, or add the free CI gate to block risky dependencies before they merge.

Scan your dependenciesAdd the CI gate