The paper is not about implementing a general attack that works on all trusting-trust mitigations.
It is precisely about showing that you can still propagate backdoored code if the compromised binary in your seed is NOT the compiler.