Really weird, anyone have some inside gossip on what this is about?
Further, whatever they're investigating here is probably "important", for some definition of important, so they likely value the ability to lean on non-disclosure clauses etc.
I suspect it was more about going after software that was enabling piracy, those are often created by naive students who are not expecting the power of government to be unleashed on them.
Not really.
The vast majority of supply chain attacks in practice are idiots exploiting namespacing, bitflips, or typos on pypi/npm to drop miners or infostealers.
Yes, even the shit tier supply chain attacks count :)
https://www.developer-tech.com/news/2023/may/22/pypi-suspend...