This study seems flawed. It references the Xz backdoor, but then talks about malware in Linux distribution packages?
It would make more sense to study and interview package management systems like PyPy and Nuget instead.
It would make more sense to study and interview package management systems like PyPy and Nuget instead.
Debian for example packages PyPi packages and the maintainer could introduce a backdoor in the version provided by Debian. Only focusing on PyPi wouldn't catch that case.
Are researching PyPy and Pip and Nuget and VSCode Extensions and AI pickle models all exclusive?