The headline is a little misleading, this story is about the group Velvet Ant breaking into devices and replacing the login software in those devices with backdoored copies.
It is not them backdooring linux login software in the distro supply chain..