Often you'll see one attack succeed or semi-succeed, but the actual plan was a good one, and it gets copied by less sophisticated attackers that can't come up with their own plans but copy other attacks that have had some success.
While technical knowledge is required to execute this, the social engineering aspect is more accessible. Backdoors aren't too hard to find and add even if you're not super technical. This means that the volume of such attacks is likely to increase and also be harder to defend against.
I'm really hoping that the XZ attack makes folks more wary though given enough time, the feeling of urgency will pass and folks may become more lax again.
Major vendors like GitHub can have a good impact here in adding detection and tools to enable detection and prevention of bad actors in this manner, though a lot of OS doesn't work around centralised tools like this and requires people to keep being vigilant.
I kinda feel that it's inevitable for such an attack to take place in the future and have similarly devastating consequences. Things are just too decentralised and independent (which is a good thing) to cover all bases effectively.
We can hope that maintainers of very commonly-used packages/tools are vigilant but people are people.