I bet they intended for their back door to eventually be merged into the base Amazon Linux image.
It just requires the SSH port to be reachable unless there is also a callout function (which is risky as people might see the traffic). And with Debian and Fedora covered and the change eventually making its way into Ubuntu and RHEL pretty much everything would have this backdoor.
So the really strange thing is why they put so little effort into making this undetectable. All they needed was to make it use less time to check each login attempt.