"First, they are very few, highly trusted individuals. Second, the results of their activity is available for all to see after the fact."

A bit like Guy Burgess, Donald Maclean and co then?

We know that critical bugs can hide in plain view in open source software for years. I would be surprised if this attack vector has not been considered by actors who are prepared to take their time.

