This has me curious (as a complete crypto noob): how would one defend against such a MITM attack in general?
Only send messages to vendors with known "trusted" keys and don't trust new keys? So in general, use a trusted channel for key exchange separate from the communication channel so that a MITM needs to control both channels?