Why
The PoC studies the maintainer-trust attack rather than the payload — how a patient contributor earned commit rights — because the human supply chain is the vulnerability here.
How it works
Not yet built.
Workspace Index › Dev Notes › XZ Utils backdoor — a supply-chain attack that almost shipped
#177PoC
The 2024 XZ backdoor was a multi-year social-engineering campaign that planted an SSH bypass in a core Linux compression library, caught by luck days before wide release.
The PoC studies the maintainer-trust attack rather than the payload — how a patient contributor earned commit rights — because the human supply chain is the vulnerability here.
Not yet built.
2024년 XZ 백도어는 핵심 리눅스 압축 라이브러리에 SSH 우회를 심은 다년간의 사회공학 캠페인이었고, 광범위 배포 며칠 전 운으로 발각됐습니다.
이 PoC는 페이로드가 아니라 관리자 신뢰 공격 — 인내심 있는 기여자가 커밋 권한을 얻은 과정 — 을 연구합니다. 여기서 취약점은 인간 공급망이기 때문입니다.
아직 만들지 않음.