amlweems/xzbot
notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094) observed · 2026-08-28
Health v2 · maintenance only
25/100
- Activity 0
- Release rhythm 35
- Longevity 63
Flags: no_releases no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 884
- days_rel: n/a
- days_push: 882
- n_releases_24m: 0
Adoption not part of the score
3554 stars · 235 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
A research toolkit for the xz backdoor (CVE-2024-3094) containing an OpenSSH honeypot patch to detect exploit attempts, a patch script to replace the backdoor's ED448 public key, and a CLI demo that triggers the RCE. It documents the backdoor's payload format for security research.
Use cases
- detect xz backdoor exploit attempts against ssh servers
- demonstrate the CVE-2024-3094 RCE exploit
- analyze the xz backdoor payload format
- patch liblzma to test the backdoor with a custom ED448 key
- set up a honeypot for supply-chain attack research
When to choose
- researching or teaching about the xz supply-chain backdoor
- checking whether attackers are attempting to exploit CVE-2024-3094
- reproducing the backdoor in a controlled lab environment
When to avoid
- hardening production SSH servers against the backdoor (patch xz instead)
- general-purpose honeypot infrastructure beyond this specific CVE
- projects requiring a maintained, licensed dependency
Facets
cli-tool · maturity maintenance
security penetration-testing reverse-engineering cli security developer-tools operating-systems go python cve-2024-3094 xz-backdoor supply-chain-attack honeypot exploit-demo openssh linux
1 source
- readme: https://github.com/amlweems/xzbot · fetched 2026-08-28 · 581583cdfa1f
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| amlweems/xzbot | main | 25 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem