Now I have to wonder if this bug report I did ~1 year ago could have already lead to discovering part of the attack. The linked binary is liblzma5.

#security #xz #liblzma #liblzma5
https://github.com/golang/go/issues/59208

debug/elf: Incorrectly double-decompressing ELF section · Issue #59208 · golang/go

What version of Go are you using (go version)? $ go version go version go1.20.1 darwin/arm64 Does this issue reproduce with the latest release? Yes. What operating system and processor architecture...

GitHub