@comex The person who did this had become the maintainer of the project. The issue was only caught at all because it caused performance issues someone looked into. It's entirely possible and perhaps even likely that there are similar, much longer term successful attacks similar to this one.
https://grapheneos.social/@AndresFreun[email protected]/112180083704855572
Since the attack was successful against Debian unstable, it's entirely possible it was used to compromise a lot of open source developers / projects and through that other projects.
I accidentally found a security issue while benchmarking postgres changes. If you run debian testing, unstable or some other more "bleeding edge" distribution, I strongly recommend upgrading ASAP. https://www.openwall.com/lists/oss-security/2024/03/29/4
@comex They also had a bunch of clear sockpuppet personas. At least one of those personas was reused a bunch of times to advocate for including their patches and then to advocate for the project adding them as a maintainer. They had commits in other projects too.
They were contributing to other projects beyond xz from the Jia Tan persona and it's quite possible they did more from other personas.
We don't really know the extent of their attacks. They may have had past successes already.