In any case, someone who can make a malicious IC die look like a balun could just as easily add their die to the EEPROM package that's intended to be there.
It makes no sense for state-level bad guys to create disguised packages and add them to boards at the assembly house. There are any number of other links in the supply chain where they could accomplish the same goal with an actual nonzero chance of getting away with it.
The key benefit of injecting at the assembly house is that it means you can target the injections based on the final customer. This reduces the footprint of the attack, which reduces the chances of your exploit being publicly exposed, and reduces the risks inherent in scaling up a highly specialised top secret supply chain.
It makes no sense for state-level bad guys to create disguised packages and add them to boards at the assembly house. There are any number of other links in the supply chain where they could accomplish the same goal with an actual nonzero chance of getting away with it.