> those doing supply chain attacks are often at least somewhat professional and take precautions.
Not really.
The vast majority of supply chain attacks in practice are idiots exploiting namespacing, bitflips, or typos on pypi/npm to drop miners or infostealers.
Yes, even the shit tier supply chain attacks count :)
Customs in the EU have massively cracked down on imports from China in the last couple of years, with new regulations regarding import charges etc.
Every single package I've ordered since then across four different EU countries and multiple Chinese suppliers has resulted in it being held until a fee was paid.
Previously, stuff below a certain value was "free".
What comedown feelings did you experience?