Hacker News new | ask | show | jobs
by raverbashing 2051 days ago
"impossible to detect" except for all the merge conflicts and build breaking changes, etc
1 comments

Huh? After the build server checks out the code, write malicious code to the source files directly just before the compilation step. No merge conflicts or breaking changes unless the added code failed to compile. It's reasonable to guess they had access to the source from the build server, so they could reproduce this environment themselves and test on their own.