"Yesterday (2021-03-28) two malicious commits were pushed to the php-src repo"

Looks like these commits were to the PHP 8.1 development branch, but the story is still unfolding and the full extent of the compromise is still to be determined, as well as whether or not some of it was pushed downstream.

