Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation
Summary
Researchers demonstrate a trusting-trust attack against an entire Linux distribution by manipulating the strip binary during bootstrapping of NixOS, enabling propagation of a payload into the final environment. The work highlights binary-level supply chain risks in open-source toolchains and the challenges of detecting such tampering, with implications for reproducible builds and trusted-build workflows.