Saagar Jha
03/31/2024
(replying to Jeremy List)
@
jeremy_list
The backdoor was definitely in the upstream git repo, but it profiled the system when configuring itself to decide whether to build the malicious code in or not