What happened here is now well documented elsewhere, so I shall not recap it much, but essentially somebody appears to have hijacked the open source XZ project by social engineering the volunteer developer into handing over maintainer access after they cited some mental health issues, used the package XZ Utils to piggy back into systemd loading liblzma, which in turn loaded XZ, allowing sshd to be hooked to trojan it on Linux distributions that use systemd.
The trojan allows somebody a private key to hijack sshd to execute commands, amongst other functions. It is highly advanced.
I think @ek mentioned this before, but I can't find it right now.
Eventually they meet at 1
I've a beautiful wife but she doesn't like popcorn.
We have to get 'samosas' for her.