Can new hardware have malicious software on it?

What are the chances that buying something like a budget keyboard off Amazon that's made in China has malicious software already on it?

I'm guessing the chance is low, but why is that? Are there third party entities that vet hardware built in other countries? Would it be relatively easy to make batches of hardware that can be connected to consumer computers all over the world to record user inputs and then send that info back to the attackers?


