Altering the flash chip would be too obvious. Looking at the flash image (dumping it) or chip (x-raying it) would be the first thing anyone would do if they suspected something fishy. Swapping a flash chip with a compromised one is a textbook 101 supply chain attack...
However a small rogue chip sitting on the SPI link (between the flash chip and the BMC) can be very sneaky: it can replace legit code with evil code ONLY when the BMC is booting up and loading code from flash. The rogue chip would not do that when the flash is read for verification (think dieselgate: a VW car disabled cheats when it detected lab testing conditions!)
Also Bloomberg talks about this rogue chip being sometimes hidden within(!) the fiberglass layer of the PCB. This is the ultimate stealthy attack. No one expects the bare PCB itself to be already compromised by a backdoor even before components are soldered on it...