Skip to main content


With regard to xz backdoor, did anyone actually have any idea this was going on? With all these vendors doing source code scanning, was there any indication of maliciousness?

#OSS #Security #SBOM #xz

a lot. But I forgot to bookmark the damn thing so I cannot link it, but it's bascially pull malware code pieces from all over the code tree, put together and do something pretty unwanted.