Maintainer compromise can use the normal release channel

When a maintainer's account is taken, the malicious version arrives through the ordinary update, signed and published the usual way.

Every automated defence that trusts the official channel passes it through. This is the hardest supply chain case, because nothing looks wrong: the source is genuine, the process is genuine, and the only anomaly is a change nobody asked for in a package few people read.

More on Software supply chain