Hacker News new | ask | show | jobs
by ColonelPhantom 812 days ago
Well, yeah. The attacker, operating largely under the name Jia Tan, has successfully manipulated the original author (Lasse Collin) to become a maintainer.

The attacker indeed laid dormant for two years, pretending to just be maintaining xz.

I really don't see any way how this wasn't malice on Jia's part. But I do think your hypothesis applies to Lasse, who was just happy someone could help him maintain xz.