people are saying the xz backdoor is likely the work of a nation state actor, and given that it appears to been slow rolled for a couple of years and immediately became obsolete before it was fully launched - you do have to admit it bears the hallmarks of a government IT project
@SecureOwl I believe it has been developed to target one specific system with known software stack and update policy.
And indeed, this nation state actor (NSA, fits there just fine lol) wouldn't want to maximize the number of affected servers. As long as they got access to the right one, that is.