Study: tampered GNU strip in NixOS seed backdoors the whole build
Julien Malka's arXiv paper describes a trusting-trust attack on NixOS via a single tampered GNU strip in the binary seed. The payload rides through bootstrap generations into the final standard environment even after the seed leaves the dependency closure.
- Attack reproduces Ken Thompson's 1984 result without touching source code
- Tampered strip infects binaries at every NixOS bootstrap stage
- Reproducible builds confirm matching hashes, not clean inputs
- Audit scope must shift from the compiler to all seed binaries
Read next
Science