Trusting-Trust Attack Hits Entire Linux Distribution via strip Utility

Trusting-Trust Attack against an Entire Linux Distribution

Ken Thompson's classic trusting-trust attack was thought to require a compiler. Researchers show it can be done with GNU strip, a utility that neither reads nor writes source code. By tampering with a single strip binary in the NixOS bootstrap seed, they implant a payload that propagates through generations of strip and survives into the final system. On a real nixpkgs revision, the attack builds a complete graphical installer and backdoors nearly all its binaries, enabling arbitrary malicious behavior.

A single tampered strip in the binary seed implants a payload that propagates from one generation of strip to the next and survives into the final standard environment after the seed leaves the dependency closure.
  1. Jach

    I'm glad they mention Wheeler's work briefly in section 7.2, since it provides a general counter to the trusting-trust attack that a lot of people seem to not know about. They dismiss it as not applying in this case, but I'm not really convinced by their argument. It's true if you only replace the compiler and run in the same environment then it won't help, but IIRC Wheeler's approach treats the environment itself as a parameter to diversify on. So not just the compiler, but also the host/OS, and even the hardware. Thus it's trivial to extend it to strip. Build binutils from source with your bad distro toolchain, fixup with your distro strip, call this build A. Then build binutils from source in a diverse environment, which includes fixup with a diverse stripper, call this B. Then do a rebuild (same diverse environment) but with B's toolchain and stripper, call this C, and compare C with A. Mismatch busts the attack.

  2. colinsane

    FYI, x86_64-linux and i686-linux nixpkgs bootstrap seed is not 25 bundled binaries, but 181 bytes, since https://github.com/NixOS/nixpkgs/pull/479322. at publication date this article would apply to non-x86 platforms like aarch64-linux, risvc64-linux, etc.

    if you're concerned about this and not on x86, i encourage you to extend this to other platforms! i believe it's possible to generalize this to every linux platform musl itself supports, in time.

  3. fjfaase

    FYI, I reviewed the live-bootstrap project that starts with a small seed. For a T-diagram that shows all processes being executed in stage0, have a look at [1].

    I did work on a solution that requires less steps, but starts with a bit larger seed (though maybe documented a bit better), see [2] and [3] for the T-diagram. Also has targets for x86_64 and arm64. (Work on RISC-V has started.)

    [1] https://fransfaase.github.io/Emulator/tdiagram.html

    [2] https://fransfaase.github.io/MES-replacement/

    [3] https://fransfaase.github.io/MES-replacement/Tdiagram.html

  4. hardwaresofton

    Guix has a full source bootstrap, by the way:

    https://guix.gnu.org/en/blog/2023/the-full-source-bootstrap-...

  5. rep_lodsb

    This is basically an ELF executable file infecting virus, nothing novel about that.

More from this day

2026-09-07