28
Thoughts on the xz backdoor: an lzma-rs perspective | Blog
(gendignoux.com)
Welcome to the Rust community! This is a place to discuss about the Rust programming language.
Credits
I'm not saying incomprehensible build scripts are good here, my mistake for making it seem that way. I'm not confident that hiding it elsewhere would have been strictly more obvious but it absolutely could have been.
I've done some pretty complex C projects and haven't had build scripts nearly that large. This one seems particularly unwieldy and certainly helped the attacker.