"There are no known reports of those [backdoored xz] versions being incorporated into any production releases for major Linux distributions"It's the one single big difference between npm and traditional distro packages - a bad upstream change doesn't instantaneously propagate to all end users within a picosecond.