Trusting-Trust Attack Demonstrated via Binary Manipulation of GNU strip, Expanding Supply Chain Threats
A new arXiv preprint demonstrates that a trusting-trust attack—previously associated mainly with compilers—can be executed using GNU strip, a common binary utility. By tampering with strip in the NixOS build process, the researchers show that a backdoor can propagate to nearly all binaries in a Linux distribution's graphical installer. This reveals that the attack surface for such supply chain threats is broader than previously recognized.
Why it matters: The finding highlights a significant expansion of potential supply chain attack vectors in Linux distributions, raising concerns for software integrity and security.
Full story at: arXiv Cryptography and Security ↗