Trusting-Trust Attack Against an Entire Linux Distribution via strip

signa11 · hn · 2026-09-05

A new arXiv paper demonstrates a variant of Ken Thompson's classic trusting-trust attack that uses the innocuous-looking strip utility to backdoor an entire Linux distribution's build chain, keeping malware invisible at source level and persistent across rebuilds. The work extends the attack from a single compiler to distro-scale, showing supply-chain audits must cover every build tool.

Original post →

More from Safety

Safety channel →