This is about the xz supply chain attack I boosted earlier. (The oss-security post [EDIT: that's https://www.openwall.com/lists/oss-security/2024/03/29/4] is clear, informative and horrifying; you should read it. The entire open source ecosystem is funded on trusting that something like this would never happen.)