My attempt to summarise what happened:
* xz is an archive file format widely used on various Linux distributions for packaging and other purposes
* The primary (unpaid hobbyist) maintainer isn't able to maintain it effectively (health issues/frequent internet breaks).
* A contributor over the course of 2+ years has submitted hundreds of (originally believed legit but now considered sus) patches and gained trust of maintainer.
* Contributor was given ability to sign releases…
1/