What's wild about this is…
… either the contributor was playing the long game - gained the trust of maintainers via legit work just to get to this point…
… or the legit work wasn't legit and they introduced other vulnerabilities over the course of 2+ years - and this exploit was the first one they got caught doing…
…or was legitimately contributing until they themselves were compromised (ship this vulnerability or we break your legs…)