Why not? The three letters are not going to send their backdoored patches under a pseudonym people like you would find suspicious. They would send it (and very likely are doing that already) under the name of "James Smith".
You really should check out much much code in e.g. the Linux kernel is written outside of "the West". It's not the 90s anymore.
You really should check out much much code in e.g. the Linux kernel is written outside of "the West". It's not the 90s anymore.