Keep OSNews alive by becoming a Patreon, by donating through Ko-Fi, or by buying merch!

How NixOS and reproducible builds could have detected the xz backdoor for the benefit of all

Some more light reading:

While it was already established that the open source supply chain was often the target of malicious actors, what is stunning is the amount of energy invested by Jia Tan to gain the trust of the maintainer of the xz project, acquire push access to the repository and then among other perfectly legitimate contributions insert – piece by piece – the code for a very sophisticated and obfuscated backdoor. This should be a wake up call for the OSS community. We should consider the open source supply chain a high value target for powerful threat actors, and to collectively find countermeasures against such attacks.

In this article, I’ll discuss the inner workings of the xz backdoor and how I think we could have mechanically detected it thanks to build reproducibility.

↫ Julien Malka

It’s a very detailed look at the situation and what Nix could to prevent it in the future.

4 Comments

  1. 2025-03-26 4:22 am
    • 2025-03-26 12:13 pm
  2. 2025-03-26 10:55 am
  3. 2025-03-26 1:05 pm

Leave a Reply