It's a docker image, NOT qbittorrent.
But there’s no evidence presented that it was hotio’s docker image on GCHR which was compromised, and there is reason to believe it might be an older, vulnerable version of qbittorrent in the docker image which was compromised.
The vulnerability: (credit crtasm)
https://torrentfreak.com/qbittorrent-web-ui-exploited-to-min...