This would have been in early 2000's, when all the major AV products - particularly those doing mail gateway scanning, were vulnerable to them. At first it was a zip attachment, expanding to several GBs. That got patched. Then it was bzip2. That got patched. By the fourth iteration, the companies finally caught up with what was being done and took active countermeasures in their software to protect themselves.
One of the first ones I remember was to limit the unpack memory and if the attachment was getting allocated too much, give up. If I recall correctly, it took a couple of weeks before malware authors came up with the idea of padding their executable payloads with a few tens of megs of leading NOPs...
Coincidentally, https://github.com/ronomon/zip can catch David Fifield's zip bomb.