It's not just educational desktop environments: this issue affects Raspberry Pi OS Lite which is the primary operating system for Raspberry Pi's used in embedded and IoT applications. Some of which have automatic updates (called "unattended upgrades" in Debian parlance).
Technically it does grant another avenue of supply chain attack... but if Microsoft run mirrors are being compromised then we probably have much bigger issues than some raspberry pis.