Nevertheless, they got caught. So big respect for the analysis. Amazing work.
That being said, what does this attack tell you about the future of software security? Free software could easily be compromised by having a highly paid team create such a payload and then convince some maintainer, one way or another, to deploy it.
How do we back off from that cliff?