Russian tech nerds are not the guys sending us nastygrams from Roskomnadzor or fining a company more rubles than there are atoms in the universe
The problem is that you can't really know that. Even if a Russian contributor living in Russia has the purest of intentions and just wants to write good code, it's easy to imagine him getting either coerced into doing something or just straight up replaced. How would anyone seriously notice? Most people are just familiar with the terminally online lolcow FOSS people who whine 24/7 about trans rights in database software on twitter, but by far not all are like that. Many do little more than purely topic-related discussion on mailing lists. You'd not notice if email accounts switched hands.
The supply chain attack on xz probably came from China. The west has a hard time understanding that these are not friendly countries and that their interests are fundamentally incompatible with ours. They cannot be paid off either, which as westerners, was our usual goto. Globalization and the idea that the universal language of the dollar can bridge everything obviously did not work out; turns out your enemies will just take that dollar and buy a knife from you to immediately stab you with it. Sanctions are also meant to be punishing and isolating to the target, that's the entire point. These bridges to Russia have and are being burned with a purpose and these people aren't just bystanders that got accidentally hit by too coarse definitions - this is pretty much working as designed. The world of academia has seen this happening already for a while by now and it's an absolute massacre of expelling and firing. I know this is an unpopular view especially in counter culture places like kiwifarms and online propaganda from these countries made these stances even less popular, but we are in a covert war against an enemy that means harm and has the means to cause it. This is in full motion wherever anyone likes it, or not. Pretending it isn't happening won't make it go away. In the US, even voting for someone who'd back out of supporting Ukraine would only at best delay the inevitable confrontation with these countries, if even that. In fact, it might accelerate it if they sense weakness and start pushing more aggressively until backing down isn't an option anymore. In the world of global politics, might makes right. Peace cannot be reached by surrendering to your enemies demands, no matter how important these demands to you truly are. That's humans for you.
I don't have anything against russian or chinese people (especially considering my personal connection to Russia) but there's a limited amount of trust you can have for people that are from there in things like this. When push comes to shove, I trust a german, american, british or french contributor intrinsically more. Yes, these might be government plants implementing backdoors too, but at the end of the day, they most likely do it for the benefit of my side. I'm aware that sounds bleak but it is what it is.
Because they don;t actually use it for anything else.
It's because they don't know how anything works and also don't care to learn. I have a very special, passionate, niche hate for these assholes.