A related discussion:
https://news.ycombinator.com/item?id=48443135The linked story includes some details on how this sort of attack works when a developer opens an infected project. This could be very important if you use a lot of open source projects in your project.