@inproceedings{scored-2026-trusting-trust,
  author = {Julien Malka and Aman Sharma and Martin Monperrus and Stefano Zacchiroli and Théo Zimmermann},
  title = {Trusting-Trust Attack against an Entire Linux Distribution through Binary Manipulation},
  abstract = {Ken Thompson's trusting-trust attack, in which a compromised compiler backdoors the programs it builds and reproduces the backdoor in subsequent rebuilds of itself, is often regarded as a threat specific to compilers. We show that it is not. We construct a complete trusting-trust attack around GNU strip, an ordinary build utility that neither inspects nor generates source code, using only manipulations of finished ELF files. In one bootstrap execution of the NixOS Linux distribution, a single tampered strip in the binary seed implants its payload into each later strip rebuilt from unmodified source. The infected strip in the final standard environment can then implant the payload into binaries of downstream packages, even though that environment has no runtime reference to the bootstrap seed. On a real nixpkgs revision, the attack builds a complete graphical installer without failures and backdoors almost every one of its binaries, enabling arbitrary malicious behavior of the subverted packages.},
  publisher = {ACM},
  year = {2026},
  doi = {10.1145/3848003.3848012},
  booktitle = {ACM Conference on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED'26)},
}
