Are you affected by the 2024 backdoor in xz-utils?

Yesterday (2024-03-29) a backdoor was discovered in xz-utils 💔. It made the rounds on all social media opsec channels.

You can read the full disclosure here and. here.

As the only affected versions are 5.6.0 and 5.6.1, you can check if you are affected by running the gist below. on a fleet of servers.

https://gist.github.com/gorillamoe/5922aa7b410ea6f03a57d25490492c02

If you are affected, you should upgrade to a newer version of xz-utils, or disable SSH on the affected servers.

Stay safe out there 🙃!