Yeah, that’s a good point. And even if distribution packages themselves are fully audited, one could attempt to compromise one of the thousands of upstream projects. Compromising a single widely-used package will give you a backdoor into all distributions, so why just focus on one?
I don’t want to name and shame projects, but I have seen at least one fairly widely used project where someone with a very short history with the project and seemingly appearing out of nowhere got commit rights. Many open source projects are very understaffed, so it’s fairly easy to become a contributor with a commit bit.