• capt_kafei@lemmy.ca
    link
    fedilink
    English
    arrow-up
    73
    ·
    1 year ago

    Damn, it is actually scary that they managed to pull this off. The backdoor came from the second-largest contributor to xz too, not some random drive-by.

    • Alex@lemmy.ml
      link
      fedilink
      arrow-up
      28
      ·
      edit-2
      1 year ago

      Time to audit all their contributions although it looks like they mostly contribute to xz. I guess we’ll have to wait for comments from the rest of the team or if the whole org needs to be considered comprimised.