The typical attack vector for any system would be compromising the inbound software. This is really easy to do when people are downloading and installing random programs from websites. This used to be less common, but popular cutting edge tools have popularized it recently "distro packaging is too slow, etc, curl|bash to install"
On linux, most base software comes from the distro repositories. The question there is how hard it would be to compromise these systems (including one of the mirrors). This includes ancillary packaging systems (pip, cpan, gems, conda, etc)