For any arbitrary language you define, I can create a known-bad library and punch it into the download stream
If you want to mitigate supply-chain attacks, you need to look at all of the following (at least!):
- library source
- file-signature
- signature key-verification
- static analysis of library functionality
- processor-dependent rogue behavior detection
- OS-dependent rogue behavior detection
This is not a language problem - this is a source and runtime problem