NSA in Amerikkka has been targeting the tor browser and flagging tor traffic for a long time. They will toss intercepts to law enforcement occasionally to be used through parallel construction. They’re fond of backdooring security software and hardware and sneaking it into the supply chain.
Hard but not impossible. It’s been done. XZ Utils, phpmyadmin, OpenBSD’s IPSEC stack