The problem is that it would require compromised people in several places at the subcontractors, because the design files for the PCB must be replaced wherever the PCB is made and in another place, at the PCB assembly, the pick & place document must be replaced and an extra reel with the backdoor component must be mounted on the equipment and that reel must come from somewhere else than from the normal suppliers of the assembly line without raising suspicions.
It can be done, but many accomplices are required. Because most of the time the backdoor component will pass the SPI data signals transparently, it will not be detected at any electrical testing and the usual optical inspections are unlikely to detect such a small change.
I am using many Supermicro motherboards, so I am wondering if this story is true. If it were true, it would not be much of a surprise, because they did not do something really novel but they just matched what USA also did, e.g. in the Cisco case.