For everyone else? Not much different to open source.
What if the entire company is a bad actor?
Although, I can imagine a sub-sub-contractor identity being somewhat easily forged, it's still harder than just creating a GitHub account.
Very doubtful in my eyes. Very few companies have the strict validation which would be required to catch this.
Good validation that goes into central components is often skimped on arbitrary deadlines, which companies are full of. On something tangential like this I suspect nobody would really notice.
I can also hear the "I noticed now there's an extra delay which isn't supposed to be there, can I investigate?" "Sorry, but this is not critical for this deadline" agile mentality.
But, as I said, maybe tricking a sub contracting company into hiring you is not as hard. I remember working with contractors whose faces I've never seem on video, let alone in person.
On my current jig developer churn is not high, yet I've only recently met developers hired 6+ months ago. I know first-hand only a handful of the committers I see. Barely know the most common commiters. I generally do watch commits of the trees/projects I'm interested into, but I'm a minority, and such behavior wouldn't catch something similar to the xz situation unless I'm absolutely lucky.
This also ignores the fact that you can just as well corrupt a current employee.
And corrupting an employee doesn't sound that easy, either. I mean, we do get paid above average.
That still leaves shit third party contractors and compromising employees computers/accounts, though.
Some underpaid indian contractor you mean?
I'm sure they'd never ever possibly accept a bribe!