That would seem to be a harder problem for the NSA. First, it has to be an active attack, modifying data in transit rather than merely siphoning it off — probably tougher to cover their tracks in that case. Second, automatic updates are presumably cryptographically signed by the publisher, so the NSA also has to steal or crack the private signing key. Third, how do you target the backdoored version of the software so certain groups/people get it and others don't? CDNs don't work that way.
In the end, it seems much more practical to sneak a backdoor into the software at the source.