• arthur@lemmy.zip
    link
    fedilink
    English
    arrow-up
    13
    ·
    7 months ago

    The malicious code is not on the source itself, it’s on tests and other files. The building process hijacks the code and inserts the malicious content, while the code itself is clean, So the co-manteiner was able to keep it hidden in plain sight.