Kinda interesting - a change made by the threat actor has ended up in Windows 11 OS. Redmond bundled libarchive into the OS in the last big update, which the TA had been tinkering with.
I don’t know if the code is actually executed anywhere in Windows.