Just read a great write-up by Miod Vallat (nprofile…z3y6) on the 2002 OpenSSH trojan incident.
It's a fantastic look at early incident response, code auditing, and how OpenBSD handled one of the first major software supply-chain attacks.
Definitely worth a read:
http://miod.online.fr/software/openbsd/stories/trojan.html
#openbsd #openssh #security