An attack on the NuGet package registry shows how advanced open-source software supply chain attacks have become.