A passphrase is meaningless if the device and the firmware itself are backdoored in the first place. So you are worrying about the wrong thing here. The most important part of a hardware wallet is the seed phrase generation process and how the device keeps your key offline. The passphrase is not the essential thing that manages your seed phrase. Mostly it just a way to open/accees the device.
Using genuine firmware and using only Trezor Suite, whether or not can significantly mitigate the risk of supply chain attacks? If not, then I die.
Indeed Trezor recommend buying the devices from legitimate sources. Moreover, Do checks of the firmware of the device, Tamper-evident seals, and device casing. For further information take a look at their blog post: Stay safe shopping for hardware wallets.