March 2024 in Software Supply Chain Security

In March 2024, the software supply chain faced unprecedented threats, including one of the most advanced supply chain attacks known to date, where an advanced persistent threat actor hid a backdoor in a software package used in many Linux distributions. The Python ecosystem also found itself the target of numerous abuses, while the continued misuse of GitHub repositories for malware distribution persisted. Additionally, Tornado Cash, a decentralized privacy solution and cryptocurrency mixer on the Ethereum blockchain, fell victim to a stealthy attack.
Let’s delve into some of the most striking events of March:
Backdoor Discovered in xz: The Most Advanced Supply Chain Attack Known to Date
In what is probably one of the biggest, most advanced supply chain attacks in recent years was discovered accidentally on Friday 30th of March. The xz project, a tool used by many Linux distributions for compressing files, was compromised by a malicious actor who gradually took over the project and inserted a backdoor, allowing the attackers unauthorized access on systems that have the compromised versions installed. (report)

Over 170K Users Affected by Attack Using Fake Python Infrastructure
A software supply chain attack campaign, involving multiple TTPs, was launched by an attacker. The attacker created malicious open-source tools with clickbait descriptions and distributed a malicious dependency through a fake Python infrastructure, linking it to hijacked popular GitHub projects and legitimate Python packages. Among the victims of this attack was the Top.gg GitHub organization (a community of over 170k users) and several individual developers. The multi-stage malicious payload harvests sensitive and valuable data from infected systems and exfiltrates them to the attacker’s infrastructure. (report)

PyPi Is Under Attack: Project Creation and User Registration Suspended
On Mar 28, 2024–02:16 UTC, the Python Package Index (PyPi) suspended new project creation and new user registration to mitigate an ongoing malware upload campaign. (report)

Tornado Cash Theft Uncovered: Stealthy Attack Quietly Drains Funds from Decentralized Finance Platform for Months
The open-source codebase of Tornado Cash, a decentralized privacy solution and cryptocurrency mixer on the Ethereum blockchain, was compromised by a malicious developer. The attacker secretly embedded malicious JavaScript code within the project’s user interface, which captured and sent users’ private deposit notes to an unauthorized external server. (report)

GitHub Repos used for Distributing Malware
A report that delves into the escalating issue of malware distribution on GitHub, and underscores the diverse methods cybercriminals employ, ranging from attacks on legitimate repositories and social engineering to exploiting GitHub actions. (report)
Our team will continue to hunt, squash attacks, and remove malicious packages in our effort to keep the open-source ecosystem safe.
I encourage you to stay up to date with the latest trends and tactics in software supply chain security by tuning into our future posts and learning how to defend against potential threats.
Stay tuned…
Checkmarx Supply Chain Security,
Working to Keep the Open Source Ecosystem Safe
March 2024 in Software Supply Chain Security was originally published in Checkmarx Zero on Medium, where people are continuing the conversation by highlighting and responding to this story.
