What are some simple tweaks the "Debians" of the world can do to mitigate this kind of stuff?
Not trust "hand-curated-by-possibly-malicious-maintainers" GitHub release tarballs, only trust git commits?
Whitelist functions that are allowed to do IFUNC/ELF hooking to core OpenSSH functions?