August 14, 2026
Someone Almost Hacked the Internet… and Nobody Saw It Coming
Y’all… someone almost hacked the internet. 😳
By Mosongo Ombaba Marcarius
4 min read
And no, I'm not talking about some guy sitting in a dark room, wearing a hoodie, typing furiously while green computer code flies across the screen. 😂💻
This story is much crazier.
Because the person behind it didn't break into a computer.
He became part of the system.
And the really scary part?
Almost nobody noticed.
Let me explain.
There is this little piece of software called XZ Utils.
Now, before you start thinking, "Okay… and why should I care about some random software I've never heard of?" — exactly. 😂
Most people have never heard of it.
But XZ Utils sits deep inside the Linux ecosystem, quietly doing something very boring and very important: compressing and decompressing data.
It's one of those pieces of software that most people never think about because they don't need to.
You don't open your computer in the morning and say, "Good morning, XZ Utils. Thank you for compressing those files for me." 😭
But underneath the surface, software like this can become incredibly important because other pieces of software depend on it.
And this is where our story gets interesting.
XZ Utils was largely maintained by a developer named Lasse Collin.
Like many open-source developers, he wasn't running some giant company with a hundred programmers sitting around him.
It was basically a project maintained by a small group of people.
And then, sometime around 2021, another developer appeared.
His name?
Jia Tan.
At first, nothing seemed strange.
Jia wasn't walking into the project saying, "Hello everyone. I am here to destroy your computers." 😂
No.
He did what any normal contributor would do.
He submitted code.
He fixed things.
He participated in discussions.
He became useful.
And slowly, people began trusting him.
Think about that for a second.
If someone wants to hack your computer, you probably imagine them trying to break through your security.
But what if they don't?
What if they simply convince you that they're one of the good guys?
That's basically what makes this story so disturbing.
Jia Tan didn't need to force his way into the project.
He earned his way in.
And while he was becoming more trusted, something else was happening.
Pressure was being placed on the project's original maintainer.
People began complaining that Lasse Collin wasn't maintaining XZ quickly enough.
There were messages asking why certain contributions weren't being accepted.
Why wasn't the project moving faster?
Why wasn't someone else helping?
And eventually, Jia Tan became increasingly involved.
More responsibility.
More access.
More control.
Nothing dramatic.
Nothing that would make everyone suddenly stop and say, "WAIT A MINUTE!" 😳
And that's the genius — and terrifying part — of what happened.
The attack wasn't one big event.
It was a process.
Trust was built slowly.
Access was gained gradually.
And by the time anyone had a reason to become suspicious, Jia Tan was already in a position where his code mattered.
Then things got serious.
In early 2024, malicious code was introduced into XZ Utils.
And this wasn't some obvious piece of code sitting there screaming, "HELLO, I AM THE BACKDOOR." 😂
It was hidden.
Some of the malicious material was buried inside files that looked like ordinary test data.
And this matters because developers naturally look at source code when they're reviewing software.
They don't necessarily expect someone to hide something dangerous inside what appears to be harmless compressed data.
It was like hiding a key inside a box that everyone assumes contains rubbish.
But what was the key opening?
That's where things get really scary.
The malicious changes were designed to interfere with OpenSSH, a piece of software used extensively to connect remotely to Linux machines.
Think about the number of servers running Linux around the world.
Web servers.
Cloud infrastructure.
Data centres.
Development machines.
Corporate systems.
Government systems.
And countless other computers that most of us will never see.
Now imagine someone quietly adding a backdoor to software sitting underneath all of that.
Yeah.
😳
The compromised versions of XZ Utils were released in February and March 2024.
And for a moment, it looked like the operation had worked.
But then something completely unexpected happened.
A developer named Andres Freund noticed something weird.
He wasn't originally looking for a massive cyberattack.
He was investigating a performance problem.
That's it.
Something wasn't behaving normally.
SSH connections were taking longer than expected.
There were strange CPU usage patterns.
Something just felt… off.
And this is the part that gives me chills.
Because how many people would have seen a computer using slightly more CPU and thought:
"Eh. Probably nothing."
Most of us.
But Freund kept digging.
And the further he went, the stranger things became.
Eventually, he discovered that the problem wasn't some innocent performance bug.
There was something hidden inside the XZ software.
Something deliberately designed.
A backdoor.
And suddenly, this obscure little compression project nobody outside the Linux world cared about became one of the biggest cybersecurity stories on the planet.
On March 29, 2024, the vulnerability became public.
Linux distributions that had incorporated the compromised versions began pulling them back.
Developers started investigating.
Security researchers started digging through the code.
And everyone suddenly wanted to know the same thing:
Who the hell was Jia Tan?
And this is where the story gets even stranger.
Because Jia Tan's real identity has never been conclusively established publicly.
Was Jia Tan one person?
Was it a pseudonym?
Was more than one person operating behind the account?
Who was actually behind the keyboard?
And perhaps most importantly…
How long had this been planned?
We don't have all the answers.
There have been plenty of theories about who might have been behind the operation, including speculation about possible state involvement.
But theories are not proof.
What we do know is enough to make the whole thing remarkable.
Someone spent years becoming trusted within an open-source project.
They didn't smash through the door.
They didn't steal someone's password and immediately start causing chaos.
They contributed.
They helped.
They waited.
They gained responsibility.
And eventually, malicious code made its way into a release that could have been deployed across countless Linux systems.
And then, almost by accident, one developer noticed that something wasn't quite right.
That's the part I keep coming back to.
The internet wasn't saved by some giant security company spotting a massive red warning sign.
It wasn't saved because an alarm started screaming.
It was saved because one developer looked at a strange performance problem and thought:
"Wait… why is this happening?"
And he kept asking questions.
That's the crazy thing about cybersecurity.
Sometimes the difference between "nothing happened" and "the entire world has a serious problem" is one person deciding not to ignore something that feels slightly wrong.
The XZ incident is also a reminder that open-source software has a strange weakness.
We like to think that because the code is public, thousands of people are watching everything.
But that's not necessarily how it works.
There can be millions of lines of code.
Thousands of projects.
And sometimes only a handful of people are actually maintaining the pieces that everything else depends on.
So the next time someone tells you that hackers are always trying to break into systems, remember this story.
Sometimes they don't break in.
Sometimes they simply show up.
They offer to help.
They fix a few things.
They become useful.
They become trusted.
And one day, you realise you didn't let the hacker through the door.
You gave him the keys.