The most important supply chain is the least protected
Consider what is demanded of the supply chains the world treats as critical. A pharmaceutical manufacturer documents the provenance, composition, and testing history of every ingredient it sells. An aircraft manufacturer traces the certification history of every component it installs and holds those records for the life of the airframe. A food producer must show where an ingredient was grown, processed, and transported, and must produce that record within hours of a contamination event. Regulators audit the records, inspect the facilities, and impose consequences when the documentation does not hold up.
Now consider what is demanded of the organizations building on the digital supply chain. A team integrating a third-party script is generally not required to document where it came from, who wrote it, or what it carries with it. A company adding a content delivery integration is not required to demonstrate that what that provider delivers has been verified against anything. An operator putting a browser-based interface in front of a control system is not required to map what that interface loads before connecting it. For most organizations, in most jurisdictions, across most of this supply chain, there is no obligation to document, audit, verify, or monitor what is being integrated and executed.
This is not carelessness on anyone's part. The frameworks that would make systematic protection possible were written for components, and this is a problem of assemblies. Sophisticated tools exist for protecting individual parts. Very little exists for seeing the chain as a whole.