I thought the attack itself was version controlled via a tracked blob file used in a unit test. I believe the attack was performed by running the test suite (which modified the source code) and then compiling?
If that's the case, then anyone that ran the tests prior to building from source would be vulnerable if my understanding is right