Some of the big ones have been, typically via infected removable storage, USB devices now ala Stuxnet, or as released recently, hard drives with malicious code embedded in the firmware. But yes, an attacker gaining physical access isn't a common approach.
The point was that you seemed concerned about someone being able to re-generate your WiFi password from your computer. But if that happens, by then you've already lost the battle, they're already in.