Earlier quoted context omitted.
oh sure the criminal who put the backdoor in place, no-one's arguing his/her liability. But the point that I was referring to is any suggestion that the repo. owner who handed it over could bear any liability for doing so, I'd suggest that's not probable/practicable.
I don't see how the text of the MIT license can be construed to indemnify a negligent developer but not a malicious one.
Put it this way, I would not suggest relying on that defence in court.