Related reading
Nix on the Steam Frame
Lobstersjohns.codeslobste.rs7Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation
The authors show that the classic trusting‑trust attack is not limited to compilers: by tampering with GNU strip they can inject a payload that propagates through NixOS's bootstrap and ends up in almost every binary of the final system. The attack succeeds on a real nixpkgs revision, building a full graphical installer while backdooring the majority of its binaries.
arXiv cs.SE (Software Engineering)arxiv.org1 minpaperHN24159The xz backdoor disclosure
Upstream xz 5.6.0/5.6.1 tarballs were compromised with an obfuscated script that modifies liblzma to inject a backdoor, which activates on specific x86_64 Linux builds and slows SSH logins. The issue is reproducible, detectable via source checks, and mitigated by avoiding the tainted releases or rebuilding from a clean source.
Hall of Fameopenwall.com8 minpostmortemHN45491849Be alert: targeted attacks on prominent Rustaceans
The Mozilla Automation Team warns of a targeted social‑engineering campaign aimed at Rust community members and popular crate owners, using fake video‑call offers to deliver malware. They advise staying skeptical of cold outreach, using trusted call platforms, enabling MFA, and reporting any concerns to Rust security contacts.

