they didn't get access to "like, a billion devices". the packages were pulled offline within like 2 hours. almost nobody actually downloaded the packages in that time; this never went unnoticed for any period of time.
however, yes, there were a lot of downloads in that time (as there is at any given moment for those packages) and your point still stands; damn they could've done a lot more damage if it wasn't totally targeted at ethereum users.
just not. a billion devices kinda damage.