Pretty hard to put a backdoor in open-source code. You’re trying to hide something in plain sight.
I think that is why they were trying this first—as a dry run.