For over two years, an attacker named "Jia Tan" contributed to the xz compression library, earning commit access and maintainership, and subtly installed a backdoor into liblzma, a part of xz that's a dependency of OpenSSH sshd on various Linux systems. The backdoor allowed the attacker to execute arbitrary commands on the target system without logging in, marking a significant moment in open ...