Several actually. Pypi is regularly targeted in this way.
Hasn't happened in Debian
But how many of those attackers also had the ability to publish a github commit but didn't to remain more stealthy.
Hasn't happened in Debian