They can definitely inadvertently be part of someone's supply line. The official repository takes precedence over any locally configured repositories (say, an in-house package named libhttps).
When that package suddenly gets published onto the official repo, it may replace the intended package without the devs noticing until it's too late.
I think this is a flawed design for a package management tool but it's the tool we've got.
These packages could be random typosquats but they might also be targeted supply chain attacks against a specific company. With the CircleCI leak, the names of internal packages may just have leaked.