How is this a supply chain attack? My official debian repository have never been breached so far.
This is no different from downloading an .exe off a shady website and blindly running the .exe.
Also: https://packages.debian.org/search?keywords=download+manager... lists:
• uget: https://sourceforge.net/projects/urlget/
• kget: https://apps.kde.org/en-gb/kget/
• persepolis: https://persepolisdm.github.io/
why use "Free Download Manager" when high quality ones are already officially packaged by debian? Is this targeting new-comers from windows?