> all the major scripting languages (PyPI, Ruby gems, and npm) have had malicious packages inserted
None of those package repositories are maintained by a limited set of curators.
Debian's repositories and other linux distributions repositories are curated.
Uploading a malicious package to npm is as easy as typing 'npm publish'.
> "reflections on trusting trust"
It's a very useful piece of art and a thought experiment.
In practice, it's not interesting for the average package. Very few packages are self-hosting and in such a position to leverage that sort of clever trickery.
A good debian maintainer will also review code of their packages and make sure such trickery has no chance to be afood (e.g. by preventing a gem from downloading a custom ruby interpreter to bootstrap itself, but rather manually bootstrapping up themselves).