Next, the affected codepath skips itself if it's not executed under just-so conditions. Specifically testing to see if it's being run interactively to avoid diagnosis, and testing to see if the executed binary is sshd.
Lastly, what good reason could a compression library possibly have, for overriding encryption routines in sshd?
It's a fair question, but it doesn't survive inspection at all. This is like finding someone in a ninja suit, wearing night vision equipment, creeping around a museum in the middle of the night, with the crown jewels in a bag slung over their shoulder - and asking yourself if they're perhaps a lost tourist.
The payload already is pretty sophisticated and full of intent to both hide itself and to target sshd very specifically. And on top, there is another layer of pretty clever build infrastructure and manipulation - again with fairly clear intent to hide the inclusion of the payload. Not to take away from the discovery, but finding this was lucky.
But then you have two actions with imo fairly clear intent to hide, deceive and target security infrastructure - and then some more mundane actions become weird as well. Deactivating parts in oss-fuzz is plausible under the right conditions, but in this light? Or being pushy to get this released into newer Fedora versions - again, might be understandable and boring in other circumstances.
Staying in your example - suddenly it becomes strange that this person got lost in the museum two or three times over the last month. Or has been taking walks around the museum very often over the last weeks. Nothing illegal with those on their own, but like that?
Cumulus Linux (originally by Cumulus Networks, which is now part of Nvidia) is a Debian-based Linux distribution used the data plane in datacenters: Dell, HPE, Mellanox, Lenovo and others let customers use Cumulus Linux. That means major datacenters running a potentially-compromised Linux distribution because of the xz attack.
McAfee Linux used to be (it EOL'ed recently) a CentOS-based distribution (which in turn comes from Fedora) used for security appliances by McAfee. Back when the xz attack was initiated (Oct'21), McAfee Linux was in full support. Even more enterprise-grade appliances to be easily compromised.
As a former Debian developer, I wonder if the "must use upstream tarball" approach Debian has (or at least, when I was a DD, just a handful of years ago) makes sense. It seems if built from the git repository, this xz attack would not have succeeded.
PS: why the negatives to an honest question!???
What we don't know for sure is whether Jia Tan (whoever that might be, if it is even a single person) did it on purpose, or if they had their account compromised.