Hacker News new | past | comments | ask | show | jobs | submit login

A mirror of the offending repository created by someone else is available at [1]. GitHub should be keeping the evidence in the open (even if just renamed or archived in a safer format) instead of deleting it/hiding it away.

The offending tarball for v5.6.1 is easier to find, an example being.[2]

m4/.gitignore was updated 2 weeks ago to hide build-to-host.m4 that is only present in the release tarball and is used to inject the backdoor at build time.[3]

[1] https://git.phial.org/d6/xz-analysis-mirror

[2] https://mirrors.xtom.ee/gentoo/distfiles/9f/xz-5.6.1.tar.gz

[3] https://git.phial.org/d6/xz-analysis-mirror/commit/4323bc3e0...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: