> Obviously it would help avoiding detection since the backdoor has the side effect of slowing down things.
My understanding was that this was the result of a bug? But I understand that part less than any of it, so I well could be wrong.
>And to me it's less that they don't care, more that their script probably only works or only has been tested on the ones using .rpm/.deb.
Now that, strikes me as more likely. Maybe they wanted to be relatively sure that they wouldn't be detected and needed to select a test matrix to test against (SELinux/landlock config across rpm/deb distros, versus across every distro.)
I guess what I'm getting at is... did they have an intended set of targets and knew they were running deb/rpm, on top of any other factors?