I'd actually call that quite difficult. In the case of xz it was a quite high-effort "long con" the likes of which we've never seen before, and it didn't quite succeed in the end (it was caught before rolling out to stable distros and did not successfully exploit any target). One huge close call, but so far zero successes, over almost 30 years now.
But typo-squatting and hijacked packages in NPM and PyPI, we've seen that 100s of times, many times successfully attacking developers at important software companies or just siphoning cryptocurrency.
I don’t think that there is a room for a meaningful and honest discussion about individuals in these circumstances.
Feels close to the theory behind homeopathy. If something can trigger some symptom in a healthy person, then the same something can revert it in a sick person. They just remove any trace of it from the medicine to increase the effect.
As many things go, the Smalltalk designers had this insight a few decades ago, all "binary messages" have the same precedence.
I still think it's weird, but it makes sense.