2 is full on speculation. It can be any kind of purpose.
One could research where those repos are coming from, and do forensics on who controls the trojan network. But that wasn't done, so right now, it's all speculation. Something can be very worrying without us knowing exactly what the use cases for it will be
… you also have to remember that the JTRIG leaked docs were about a decade before LLMs, so you could imagine tooling these days is 100x a they used to have