> The 0-day is in a popular software package.
(I have no idea what this is.)
> The GitHub repo apparently contains a backdoor ability to execute code from the attacker.
(This is what Google says and I think it’s the autoupdater.)
Is this different than what you feel?