# Malicious code in XZ\_jll.jl (v5.6.1+0) ; it could pose a problem?

**URL:** <https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311>\
**Category:** Offtopic\
**Tags:** security\
**Created:** [March 29, 2024, 8:58pm UTC](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311 "2024-03-29T20:58:09Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [March 30, 2024, 12:41pm UTC](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311/4 "2024-03-30T12:41:02Z")

</div>

> [@PSA: backdoor in xz-utils and relevance for the Julia ecosystem](https://discourse.julialang.org/t/psa-backdoor-in-xz-utils-and-relevance-for-the-julia-ecosystem/112328):
>
> Statement of the problem A [thread in oss-security](https://www.openwall.com/lists/oss-security/2024/03/29/4) mailing list reported that the [XZ Utils](https://en.wikipedia.org/wiki/XZ_Utils) project was affected by a [backdoor](https://en.wikipedia.org/wiki/Backdoor_(computing)): one of the current maintainers of the project appeared to have injected malicious code, included in versions v5.6.0 and v5.6.1 of the xz-utils package, that under certain circumstances could potentially compromise an OpenSSH client and obtain login credentials to remote systems. Affected systems and conditions for the backdoor to work XZ Utils is somewhat popular in Linu…

---

_[View the full topic](https://discourse.julialang.org/t/malicious-code-in-xz-jll-jl-v5-6-1-0-it-could-pose-a-problem/112311)._
