The most optimistic reason would be that they were investigating a supply-chain attack, or something of that nature.
Further, whatever they're investigating here is probably "important", for some definition of important, so they likely value the ability to lean on non-disclosure clauses etc.
I suspect it was more about going after software that was enabling piracy, those are often created by naive students who are not expecting the power of government to be unleashed on them.
Not really.
The vast majority of supply chain attacks in practice are idiots exploiting namespacing, bitflips, or typos on pypi/npm to drop miners or infostealers.
Yes, even the shit tier supply chain attacks count :)