Putting an xz Backdoor Payload in a Valid RSA Key
rya.nc
rya.nc
https://ondergetekende.nl/vanity-rsa-public-key.html
There's quite a bit of room in an RSA key for arbitrary contents, especially if you don't care about the security of said key.
https://rya.nc/cert-tricks.html
and I actually have had a vanity ssh key generator online for years:
https://rya.nc/ssh-vanity.html
I looked at your code - I was not aware of the rsa_crt_* functions, those are handy!
Your routine for picking nearby primes is interesting - are you aware of any attacks that are possible if that debiasing isn't done?