If you can't trust the team behind the distro, then sure, your supply chain is compromised, but it's significantly less likely for a single package developer to cause any damage, as all the big distros have rather extensive policy and procedures to prevent such things.
The crappy ones maybe. Proper distros build everything from source.
Linux code is always reviewed before deployment, goes through many eyeballs, people are careful about this. The same is not true of npm, or any of the other services (as this event clearly shows).
I'm talking about not just the kernel but all the various other things from libraries to servers to tools and everything in between.
The problem you describe isn't Linux, it's Linux Distributions.
Where would you draw the line?
Source packages are available, and if the binaries don't match the code a distro would soon be outed a la "many eyes" thinking.
We have to trust some or none.
Get the top off that chip, see if the factory put an extra core in for the NSA (IME).