I have a suspicion that a lot of these supply chain compromises are done by the security researchers at security vendors, selling software to protect the software supply chain. Spreading fear to create demand for their products.
Like in the good ole days of Windows 98 and antivirus era, a lot of advanced virus techniques in the wild came from the people who used to work for AV companies
That would be extremely surprising, given the number and severity of federal crimes involved.
(I also dare say: many of these attackers demonstrate a better in-depth understanding of packaging ecosystems than supply chain security vendors do.)
the federal crimes part is irrelevant if its below the threshold of federal authorities actually cracking down on them and figuring out entire chain.
just because credit card theft and other types of scam are illegal
I remember how ddos attackers created "DDOS protection" companies to protect their victims against DDOS.
I don’t think the impact of these recent malware campaigns is below the threshold for federal interest.