I built a GitHub app that detects it in pull requests, notifies or blocks them. Alongside it, I published a Semgrep ruleset for any stage of the CI/CD.
I started this after getting frustrated by all the FUD around malicious code - lots of noise, little effort to solve it. Having said that, it's still a major attack vector - a stored RCE, with the codebase itself as the sink.
You should be worried about your logs too :) Dare you to `sudo cat logs.txt`
https://www.youtube.com/watch?v=3T2Al3jdY38