It could be a toy, a common household tool or appliance, or anything else that is small and inexpensive. It more-or-less works as intended, but it also included a small robot. The packaging and marketing would be designed so you weren't supposed to notice the robot, but the packaging included the necessary fine print and an explanation that this robot was just there to make sure you got the best experience possible for anybody that spotted this "extra feature".
Unrelated to whatever it was that you bought, at night the robot would install a device on your phone that re-routed all your phone calls through my office (a MITM attack). The phone still works ok, except now calls to your favorite pizza deliver restaurant seem seem to be re-routed to the competitor across town. Some time later a neighbor complains that he can sometimes when he checks his voicemail, he gets your phone conversations instead.
After finishing with the phone, the robot does the same thing to your cable TV.
Some days, the robot would go through your (physical) mail and place stickers with new advertisements into your magazines. Occasionally one of those stickers would end up on your electric bill, obscuring important information. The power company has a similar logo to one of the sticker-ads, so the robot probably confused the two logos. Even if the robot didn't have any stickers to place, it would still open your mail and leave it (opened) on the ground near your mailbox for anybody to see.
If I rand a business that did this - possibly as my main (or only) product - how long would I be able to run this scam before someone threw me jail?
--
Intentionally breaking TLS with a MITM attack goes way beyond the usual scam/trojan. This isn't even the usual negligence that we see in the "security" of a lot of products. Creating a certificate that lets you MITM any domain is very obviously a willful act.