Looks like it's the apicredentials.h. Is this really the best way to distribute these? They must not be very secret since they're still in the .tar.xz.
I also think about this incident that could just as easily happen here, this has set us up for the same exact scenario: https://en.wikipedia.org/wiki/XZ_Utils_backdoor#:~:text=This modified file was not present in the git repository%3B it was only available from tar files