Pre-SolarWinds supply chain watershed

Before SolarWinds, which 2017 incident do you consider the watershed supply‑chain compromise from a hunting perspective? I lean toward CCleaner v5.33 (September 2017), but I hear strong cases for the M.E.Doc/NotPetya wiper wave and NetSarang’s ShadowPad backdoor — curious which one shaped your intel triage and telemetry pivots the most.

‌⁠‍⁠​‍​‍‌⁠‌​​‍​‍​⁠‍‍​‍​‍‌‍​⁠‌⁠‍‌‌‍​‍‌‍‌‌‌⁠​‍‌⁠​⁠‌‍‌‌‌‍​⁠‌⁠‌‌‌⁠​‍‌‍‍‌‌⁠‌​‌⁠‍‌​‍​‍​‍⁠​​‍​‍‌‍‍⁠​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠‌‌⁠⁠‌⁠‌​‌‍⁠⁠‌⁠​​‌‍‍‌‌‍​⁠​‍​‍​‍⁠​​‍​‍‌‍‍‌‌‍‌​​‍​‍​⁠‍‍​‍​‍‌‍⁠‍‌‍‌‌‌⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‌​​‍​‍​⁠‍‍​‍​‍​⁠​‍​⁠​​​⁠​‍​⁠‌‌​⁠​‌​⁠​‌​⁠​‌​⁠‌⁠​‍​‍​‍⁠​​‍​‍‌‍‍​​‍​‍​⁠‍‍​‍​‍​‍⁠‌‌⁠‌​‌⁠​‍‌⁠‍‌‌‍⁠‌​⁠​​‌​‌‌‌‍⁠​‌‌​​‌‌‍‌​⁠​‌‌‌​‌‌​‍‌‌‍​‌‌‍​⁠‌​‍‍​‍​‍‌⁠⁠‌​