« Half a Second » : the XZ backdoor finally tells its story in a book

Cybersecurity yesterdayAdd to bookmarks

« Half a Second » : the XZ backdoor finally tells its story in a book
Illustration : Momiji Shirogane

The detailed account of the XZ Utils attack published as a book. A look back at the incident that nearly compromised the majority of Linux servers - and what the book seems to offer.

Facts

A book titled « Half a Second », dedicated to the attack against XZ Utils, has just been announced (source: half-second.com, spotted on Hacker News on July 19, 2026). The title refers to the delay—a half-second—that tipped off engineer Andres Freund and prompted him to investigate a suspicious slowness in his Debian environment.

Context reminder. The XZ attack (referenced as CVE-2024-3094) was revealed at the end of March 2024. A contributor with the pseudonym « Jia Tan » had patiently gained the trust of the XZ Utils community for nearly two years, obtained maintainer rights, and then inserted a backdoor into versions 5.6.0 and 5.6.1 of the library. This backdoor specifically targeted OpenSSH via a subtle dependency chain (systemd → libsystemd → liblzma) and would have allowed an attacker knowing a private key to execute arbitrary code on any machine exposing an SSH server with the vulnerable versions.

What the book seems to bring

According to the presentation page, the book traces:

  • The long-term work of the attacker (two years of legitimate contributions) to establish his reputation in the project.
  • The psychological pressure exerted on the historical maintainer, Lasse Collin, notably via complicit personas on the mailing list who demanded faster releases.
  • The chronicle of the detection by Andres Freund and the race against time to defuse before integration into stable distributions (Fedora Rawhide, Debian sid, openSUSE Tumbleweed were already affected).

Analysis

The XZ affair remains, to this day, the most advanced example of a supply-chain attack against open-source software. What the book seems to want to document—and it's useful—is the social side of the attack: the manipulation of an exhausted solo maintainer, the slow building of trust, the use of ghost accounts to pressure publication. The code is almost secondary.

Two lessons still relevant in 2026:

  1. Solo maintainer = systemic risk. Any strategic open-source project should have at least two active maintainers and a clear succession plan. This is what the OpenSSF (Open Source Security Foundation) has been reminding us for a long time.
  2. Detection came through a curious developer. No automated tool raised the alert: it was an engineer (Freund works at Microsoft on PostgreSQL) who found it strange that an SSH took 500 ms longer to respond. Observability culture pays off.

What to do now

  • Verify that your XZ Utils park is up to date (distribution patches since April 2024). This is supposed to be done, but we continue to see poorly patched machines, especially on custom rebuilds or frozen VMs.
  • For your own open-source projects: audit your maintainers and critical dependencies. Tools like deps.dev (Google) or the OpenSSF's Alpha-Omega program give a quick view of the health of a supply chain.
  • Read the book when it comes out: case studies like this one are rare and precious for training teams to spot social engineering patterns.
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Was this article helpful?

8 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information