Or just replace an existing chip, which is the most logical way to do it...
But... why put it on an unpopulated footprint. Why not just replace the original Quad SPI IC with a backdoored device?
It’s not like doing both is extra sure, it’s just weirdly difficult and more easily detectable to do it in the way described.