XZ backdoor in a nutshell

Possibly linux@lemmy.zip to Linux@lemmy.ml – 1210 points –
162

You are viewing a single comment

The tukaani github repos are gone, is there a mirror somewhere?

Tukaani main website

Though unfortunately (or I guess for most use-cases fortunately) you can't find the malicious m4/build-to-host.m4 file on there afaik. The best way to find that now, should you really want to, is by looking through the commit history of the salsa.debian.org/debian/xz-utils repository which is, as far as I understand it, the repository that the debian packages are built from and consequently also what the compromised packages were built from.