Which if true could mean that updating your system now might actually pull in the exploit, if this isn't shipped for the particular distro.
The github comments on the first commit say that this was a rogue maintainer who had behaved well for two years.
#roguemaintainers https://m.primal.net/Hpgn.jpg