Earlier quoted context omitted.
You may have misunderstood (understandably, because the tweets seem to be deliberately misleading). These are malicious commits in forks of repositories. There is no supply chain attack unless you make a habit of taking random forks of popular projects from GitHub and inserting them into your supply chain.
> There is no supply chain attack Actually yes, this is all about supply chain attacks. Typosquatting is one of the most common methods. It goes under this category.
If you impersonated all these real repos, made npm, pypi packages for them etc and also updated the readme I think you could catch some people off guard.