Do you have any references that describe this behavior? That sounds like exactly the kind of thing that could conceal a backdoor of the sort this seems to be warning about.
installed by default in most distributions, e.g. https://packages.debian.org/bookworm/amd64/atop/filelist