Supply chain attacks have been an issue as long as you've relied on distributions. I can point to plenty examples in the wild, but you don't have wait for an incident to occur before creating a safer userspace.