Analysis of bash-stage obfuscation used to hide the liblzma/xz backdoor

Open link in next tab

https://gynvael.coldwind.pl/?lang=en&id=782

payload appears to have been hidden in test data then decrypted and injected during the build process.