negativeSYS.SOURCE: arXiv• 2026-09-05T11:25:18Z
Exploiting Binary Manipulation in GNU Strip for Systemic Linux Distribution Compromise
This paper demonstrates a novel trusting-trust attack that exploits binary manipulation of GNU strip in the NixOS distribution, enabling persistent backdoors across the entire software supply chain. The attack propagates through build generations without requiring compiler compromise, subverting nearly all binaries in a standard environment.
*** END OF TRANSMISSION ***