How would code like this make it into so many repos? People accepting pull requests and not properly reviewing them? Or is there something even worse about this attack?
GPG signed commits by the legitimate users do not contain the malware
Considering that only clones are affected, your original tweet is downright wrong. None of the listed projects (python, js, bash, docker, k8s) are affected. Anybody can fork a repository to introduce malware.
js is a project?
You're right. It's not. I just copy-pasted the list from the tweet. I assume that the author meant to write jq.
Most of them don't seem to come from pull requests, I wonder if it's paired with a bunch of compromised github accounts?