TL;DR - some deflate misuse, mixed-mode alphanumeric and numeric QR encoding, mask choice override, padding the code with content that base45 encodes to numbers only and choosing them in a way to produce a meaningful image. Apparently, verifier apps are fine with it - every one I tried scans green.
This is a non-prod demo cert used for illustration of the concept with some funny images inside:
https://i.imgur.com/3JonSRX.png
Would there be any interest in me doing a post explaining how it was done?
Also, what else should I draw inside?