An open question is why PyPI doesn’t have the same problem.
PyPI is also subject to supply chain attacks. What do you mean?