> a complex APT supply-chain attack
What do you mean by APT? If you mean Debian's package manager, that's not what this attack was. This was done upstream and affected non-apt distros just as much.
It's true that upstream is part of apt's supply chain but focussing on apt is misleading.
edit: why the downvotes? I get from the responses that I was wrong but given how the exploit was initially found in a Debian system and a lot of people very quickly jumped on the “Debian patched a thing and broke security” bandwagon, I don’t think it was much of a leap to wonder if that’s what was meant.
Acronyms and initialisms are not the best way to convey specific information.