We live in the age of vulnerabilities with their own brands and domains!
While interesting, worth knowing and certainly something to address, be aware the problem is not new. That class of issues has been known for years. “TrojanSource” advances the technique a bit, making the attack slightly easier to conduct. But it shouldn’t be perceived as some completely new thing or the end of the world.
A simple example in the attachment. Replacing characters in variables with look-alikes or making different variable names undistinguishable to human reader is another common way of performing such an attack.