A supply chain attack was identified last week and is now doing the news round.
- https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/
- https://www.theregister.com/2024/12/09/openwrt_firmware_vulnerabilities/
Builds created in the last seven days (from yesterday) seem clean but there's no guarantees about older builds.

