XZ backdoor in a nutshell
XZ backdoor in a nutshell
as long as you’re up to date on everything here: boehs.org/…/everything-i-know-about-the-xz-backdo…
the only additional thing i’ve seen noted is a possibilty that they were using Arch based on investigation of the tarball that they provided to package maintainers