If they developed an alternative version of OpenSSH with backdoor how can they distribute it so that people will actually use it?
Physical access to the target's system.
Control the network upstream of the target so that the modified checksum and package can be delivered during package upgrades.
Compromise the mirror used by the target to provide the modified checksum and package.
Hide the code changes in a series of semi-related ostensibly legitimate pull requests. Legitimise your pull requests by developing corner cases which expose "bugs" in the software you wish to attack.
Crowbar attack against the upstream maintainer.
"USB key in the carpark" attack.
Those are some ideas. I don't claim to be an expert in the area.