Notepad++ have been there too
Then you realize very popular software and their official website actually are a one man show. Nobody is perfect and those things tend to work for years without security in mind. At the time it were built, supply chain attack was not invented yet.
