On Linux, we intercept at a level where packets already have an Ethernet header. I hope that Paqet injects before* this layer, but only a test can give the proof.
A recent example, but not the only is a Iran botnet using this to get around detection.
https://cybersecuritynews.com/iran-linked-botnet-exposed-aft...