Veritasium has a great video explaining the XZ backdoor exploit from a few years ago: https://www.youtube.com/watch?v=aoag03mSuXQ
The Internet Was Weeks Away From Disaster and No One Knew

YouTube