- cross-posted to:
- security@lemmy.ml
- cross-posted to:
- security@lemmy.ml
You must log in or register to comment.
Damn, it is actually scary that they managed to pull this off. The backdoor came from the second-largest contributor to xz too, not some random drive-by.
Time to audit all their contributions although it looks like they mostly contribute to xz. I guess we’ll have to wait for comments from the rest of the team or if the whole org needs to be considered comprimised.