Supply chain attack is a trust issue. I don't know what these tools do but if it's software then there is one more link you must trust in supply chain.
Solution is to go the other way , you don't bloat your software with too many dependencies. That way you minimize your attack surface.