Most useful write-up I've seen so far, from @eb:

Everything I know about the XZ backdoor
https://boehs.org/node/everything-i-know-about-the-xz-backdoor

Everything I know about the XZ backdoor

Please note: This is being updated in real-time. The intent is to make sense of lots of simultaneous discoveries

Quite the traffic spike, this (switch to 90-day stats).
https://espy.boehs.org/share/JGBYO4bVg3kZVQUb
Can I just mention that if you haven't read this, it's another very interesting piece from @eb:
https://boehs.org/node/npm-everything
NPM Install Everything, and the Complete and Utter Chaos That Follows

how one little joke can get so, so out of hand

@xahteiwi @eb @zhenech No THAT’S the flavor of True Crime that hooks me. Good write-up, thanks for sharing.