JWF edit: More about this now on the Fedora Magazine: (correction to the Fedora Magazine article: testing updates are not opt in in F40 but enabled by default because it is a pre-release; see update 2 below) The xz package that has already entered the current F40 pre-release versions/variants and rawhide contains malicious code. This does NOT affect users of the Fedora releases (F38, F39 are thus not affected), but all users who use already F40 pre-release versions/variants or rawhide shal...
And the one main issue with FOSS rears its ugly head – freedom of contribution also means freedom of bad contributions.
This happens in close source software too. You just don’t find out about it until it gets bad enough.