http://red.ngntfwmwovvku6eqi7dzzgzv2wzlvq2cqtqha7ccgzub2xnivsuxnuyd.onion/r/privacy
As far as I understand it, this way malicious code could be injected into a build that would still be signed with F-droid's signature, if somehow the F-droid srrvers were to be attacked. But this is also quite unclear because I read on some forum post that apps published on F-droid are built and signed in a VM, so one would need to permanently infect the VM in order to infect the apps?