I use python professionaly. Never seen a real successful supply chain attack on libraries used by “normal” people. There was recently a supply chain attack to pytorch, that I remember, but it was solved within few hours.
It is not a real risk for non developers. It is a risk, but veeery low, miles lower than pdf.exe.
Just check this stat for ransomwares taken as an example of viruses: https://www.statista.com/statistics/701020/major-operating-systems-targeted-by-ransomware/
Windows server is ~20% of server market. Still it is there second, with in practice no GNU/linux (80% of server market). This is why people do not really worry much, the risk exists, but it is minimal for well configured system compared to competition, even where competitors are a niche and Linux machines are the main target.
On windows, an antivirus is not a bad idea… On Linux, a firewall and basic care are usually sufficient
It targets router firmwares though… These bot farms do not usually target real gnu/Linux os, because it is easier and more effective to attack router firmwares that are not well configured by producers and telcoms, and are practically never upgraded.
Therefore they are not a real threat for standard mint or popOS user… Let alone gentoo users
Edit. See https://en.m.wikipedia.org/wiki/Mirai_(malware)