I love how you describe this as “pushing malware to random servers”.
Maybe if he included a backdoor in previous versions and now dispatched infinite loop from his C&C server, sure. But he published a new version of his library, which was literally pulled by the affected parties.
I’m pretty sure that was illegal in the US, but that’s multiple-felonies-a-day-land anyway.