A researcher has discovered a sophisticated backdoor in the xz sshd, which allows for remote code execution and potentially full authentication bypass. The backdoor is triggered by sending a crafted command to the RSA_public_decrypt hook, and it involves a complex process of installing another hook and sending fake ssh-rsa pubkeys. The researcher has confirmed the existence of the backdoor and is still exploring its functionality. The discovery has sparked a discussion about the potential for other undetected backdoors in open-source software.