

It was xz, a software most people probably use without even knowing it as it is a library which is included in a lot of other projects. The vulnerability targeted openssh which is one of these users.
That being said: Do you also audit the dependencies of the software you’re installing? I usually don’t, unless a customer pays me for it. However, before I pull any dependency into one of my own projects I take a look at it’s dependencies. If a library for a simple task brings tons of dependencies with it, I rather not use it.
Back in the good old days I used to play kmem-roulette: Write a random value into a random address of /proc/kmem until the system crashed. That was much more fun, as on the way there was also the possibility that the kernel might just start wreaking havoc in some random files. No wonder they removed the kmem file in the end.