A backdoor was discovered in xz/liblzma, affecting OpenSSH server, which was hidden in test files using obfuscation methods. The backdoor was extracted and executed through a series of bash scripts and commands. The article explains the obfuscation methods used, including substitution ciphers and an RC4 variant implemented in AWK. The backdoor was found in versions 5.6.0 and 5.6.1 of xz/liblzma.