The xz attack shell script was a sophisticated supply-chain attack that targeted the xz compression library. The attack involved adding a malicious script to the library's build process, which was hidden in a test file. The script was designed to inject malicious code into the library, allowing attackers to gain control of systems that used the library. The attack was discovered after a researcher noticed unusual behavior in the library's code.