The present case also just seems malware easily detected by VirusTotal: https://old.reddit.com/r/xubuntu/comments/1oa43gt/xubuntuorg...
But nobody wants to talk about true security. For example, why does a Python module that renders progress bars (for example) need my full trust about what it does to the rest of my system? Etc.
Sorry, patient, why are we talking about setting your broken arm when you are genetically predisposed to cancer that's going to kill you anyway?
tqdm is pure Python and available as a wheel. Or is this a general complaint about sandboxing others' code at runtime?
Of course, there are people who disable built-in security scanning and don't use another antivirus software, and that's on them.
Nobody spends energy worrying that the universe is an evil compiler that warps reality specifically to target us. Because 1) it's unlikely, and 2) if it were true there's no change in defensive posture that would help. It's the same for most individuals when considering being targeted by state actors. Unlikely, and not defensible, so no point hand wringing.
Though, I also doubt, they would just shelve these epic exploits, since a universal Linux backdoor likely puts themself at risk too, unless you can pull off a grand conspiracy, or deliver patched packages to your own people without questions asked. Maybe a completely locked down country like North Korea could do it. I doubt many other countries got an incentive, unless in preparation of a specific attack.
I have not heard that specific scenario yet, but indeed quite similar ones from very depressed/mentally ill people. Basically that the whole universe was created to torture them specifically. (Probably there is even a medical term for that)
But yes, a sane person should rather be concerned to not fall scam to one of the various criminal groups. That is a real cyber threat for most people and companies.
So minding basic security helps, even if the NSA will likely get past that in no time.