RedHat is reporting that the official upstream of xz, a common library on Unix systems that you've probably used via the tar command, contains malware. The full report is at https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users and it's CVE-2024-3094.