| He should have sat on the password. He should have watched for PRs, and started pushing updates immediately after they had received approval, and then merging. Instead, he panicked and kicked out all the maintainers, who realized the intrusion only 10 minutes after he gained access. And all he did was add `rm -rf /*` to build scripts, and the N word to the readme. The malicious commits: https://github.com/gentoo/gentoo/commit/e6db0eb4 https://github.com/gentoo/gentoo/commit/afcdc03b https://github.com/gentoo/gentoo/commit/49464b73 https://github.com/gentoo/gentoo/commit/fdd8da2e https://github.com/gentoo/gentoo/commit/e6db0eb4 https://github.com/gentoo/gentoo/commit/c46d8bbf https://github.com/gentoo/gentoo/commit/50e3544d |