This isn't hypothetical either - back in June it came out that a popular CDN hosting JS polyfills had been sold to a new provider and was distributing malware inside the legitimate scripts that sites were loading. It impacted a 6-digit number of websites and anyone who used them, and it turned out that this had been going on for months.
