GitHub Takes Down Central Repo for XZ Compression Tool Due to Malware Violation and Security Concerns

5 months ago 1322

GitHub has taken the xz central repo offline. According to the platform xz violated the terms and conditions. Earlier this week malware appeared to be sent using the compression tool leaving many Linux distros vulnerable.

The repo tukaani-project/xz can no longer be found on GitHub. The platform says it disabled the repository itself because it would violate GitHub's terms of use although it did not provide details. GitHub does not allow malware.

The compression tool xz came in the news on Friday when it turned out that it may contain malware. Versions 5.6.0 and 5.6.1 appear to contain a backdoor that makes it possible to take over SSH connections among other things. Much is not yet known about this but it now appears that someone has placed malware in the repo in the hope of spreading it to multiple Linux distros.