https://www.openwall.com/lists/oss-security/2024/03/29/4
https://news.ycombinator.com/item?id=39865810
睡醒打開電腦就發現 xz 被下蠱的消息,而且是埋了兩年的 social engineering (這麼刺激?):
He has been part of the xz project for 2 years, adding all sorts of binary test files, and to be honest with this level of sophistication I would be suspicious of even older versions of xz until proven otherwise.