The "malice" aspect is a great one and I did not go into that in this post because of course back in the 1990s we were not at all concerned that someone would maliciously craft inputs that would slow down this algorithm.
In modern code we'd want to do a threat model that considered the consequences of untrusted inputs.