Copies of OpenSSH packages on popular download sites have been trojaned, developers have warned. Overnight it was realised that the tarball for OpenSSH 3.4p1 on the main openBSD (ftp.openbsd.org) mirror was compromised, after developers noticed that the checksum of the . . .
Copies of OpenSSH packages on popular download sites have been trojaned, developers have warned. Overnight it was realised that the tarball for OpenSSH 3.4p1 on the main openBSD (ftp.openbsd.org) mirror was compromised, after developers noticed that the checksum of the package had changed. Other mirror sites might also be affected.

The malicious code is not particularly sophisticated but it is a remotely controllable program that could give potential attackers root access to victim's machines. The backdoor is in the makefile that comes with the package, not the OpenSSH software itself.