The BMC is an ARM microcontroller that has complete access to everything, exactly like the Intel Management Engine, but the server vendors prefer a separate chip for the same job. What is described in the article is very easy to do by inserting a microcontroller on the SPI link that connects the BMC with the flash memory containing the BMC programs, which are copied from there to a RAM at boot.
However, such a microcontroller would need 8 pins for at least 7 signals: ground, power, SPI clock and 4 SPI data, to and from BMC and flash memory.
Nonetheless, 8-pin packages can be very small, e.g. 0.8 mm by 1.35 mm, i.e. only slightly larger than 1 square millimeter.
So from a technical point of view, all is easily feasible.
The problem is that it would require compromised people in several places at the subcontractors, because the design files for the PCB must be replaced wherever the PCB is made and in another place, at the PCB assembly, the pick & place document must be replaced and an extra reel with the backdoor component must be mounted on the equipment and that reel must come from somewhere else than from the normal suppliers of the assembly line without raising suspicions.
It can be done, but many accomplices are required. Because most of the time the backdoor component will pass the SPI data signals transparently, it will not be detected at any electrical testing and the usual optical inspections are unlikely to detect such a small change.
I am using many Supermicro motherboards, so I am wondering if this story is true. If it were true, it would not be much of a surprise, because they did not do something really novel but they just matched what USA also did, e.g. in the Cisco case.