Stembolt Here's the important part:
Kaspersky says it can’t “confirm with certainty the infection was a result of a supply chain attack or deliberate action by the developers.” The company names two AI chat apps that seem to have been created for the campaign and appear to still be available on the App Store, called WeTink and AnyGPT. Additionally, Kaspersky found the malicious code in a legitimate-seeming food delivery app called ComeCome, which you can also still download.
WeTink has been on the App store 5 months, AnyGPT popped up in the App store 2 weeks ago, and ComeCome has been available 2 years.