You must log in or # to comment.
Here is more info on this:
https://lwn.net/SubscriberLink/1077035/c7e7c14fbd60fae9/
(I hope sharing this link is OK, Linux Weekly News is high-quality, ad-free, and funds itself with subscriptions.)
There exist speculations that this could be a clumsy attempt of an attack similar to xz-utils, where the project was taken over overworked maintainer by a malicious actor that inserted exploit code (well hidden in binary test data) which was triggered on distributions build servers.
Who’s Nathan? Is he a Fedora Dev?

