So, did they have time for a git blame yet? It's one thing to say you have found a backdoor, another is to clear up how it got there in the first place.
Is it possible to prevent history of the code being modified? Do DVCS use blockchains?
* Compromised build script - probably under source control as well? * Compromised compiler - If the attackers had this level of access, they probably had enough access to erase logs showing who/when the compiler was replaced * Binary patch the compiler output - Not impossible (though I suspect unlikely?) that the original source and build system are clean, but the binary is tampered with after the fact.