Earlier quoted context omitted.
> someone in the design lab (not in production) downloaded infected firmware from SM's support site Other than the claim that the infected firmware is "still hosted there" (which beggars belief) that sounds more like an engineer was spearphished and fooled into downloading firmware from what he believed to be the SM support site.
FYI "still" meant as of the time of the follow-up reporting in 2016, not today. I think it's believable that SuperMicro's support site got hacked. But I agree that was an incident on par with a sole developer installing malware on their system, not a supply chain compromise or major security incident with production systems.
Much discussion about software supply chain attacks was around the role of NPM as a vector, which can be thought of as a source of "drivers" that make various products and services work, similar to the role that a support site for a physical manufacturer plays.