The Backdoor Was Already in the Book
Nadia Eghbal spends a chapter of this book on an incident from November 2018: Dominic Tarr, the author of a widely-used npm module called event-stream, hands commit access to a stranger who asks nicely. The stranger inserts code that tries to drain cryptocurrency wallets from an app several layers downstream. Tarr, when developers call him irresponsible, shrugs. He compares the whole arrangement to being promoted from dishwasher to cook for fifty cents an hour more — more responsibility, same lack of pay, and eventually you stop caring who you hand the kitchen to. Eghbal uses the story to illustrate a structural point: that open source maintenance runs on attention, not labor, and attention is a depletable resource that nobody is obligated to keep spending once the reputational payoff flattens out.
In March 2024, a maintainer using the name Jia Tan — after two years of patient, unpaid, technically excellent contributions to a compression library called xz-utils — inserted a backdoor into the SSH authentication path of most Linux distributions on earth. It was caught by accident, by a Microsoft engineer named Andres Freund who noticed his server was 500 milliseconds slower than it should have been. Read Eghbal's event-stream chapter now and it is not a case study anymore. It is a schematic. Every mechanism is present: the burned-out original author, the patient stranger offering to help for free, the handoff that looks like generosity because there is no other model for succession, the total absence of any institutional actor whose job it was to notice. The scale is different — a crypto wallet versus the encrypted backbone of the internet — but the shape is identical, which means the book didn't predict an outlier. It described a load-bearing pattern six years before the pattern produced its worst possible instance.
Where the book is less prescient is in its proposed fixes. Eghbal's later chapters build toward funding models — GitHub Sponsors, Open Collective, corporate sponsorship arrangements like Trivago's for webpack — as the mechanism that closes the gap between value extracted and labor compensated. Some of this happened. Tidelift, the OpenSSF, a genuine post-Log4Shell surge in foundations willing to write checks. But none of it touches the actual vulnerability that xz-utils exposed, which was never a money problem. Jia Tan didn't need a grant. He needed two years of patience and a maintainer too exhausted to keep checking who he was. Money can relieve burnout; it cannot audit an identity. Eghbal's framework, built around attention as the scarce resource, correctly diagnosed why maintainers hand off access to strangers — and then the industry spent five years building