FINALLY!! All the podcasts, all the posts, tweets about all this never made any sense until this write-up. This makes 100% sense now.
TLDR:
* AWS key exploited
* Malicious JS targeted for one by modifying it in the S3 bucket
Thanks Jameson Lopp (nprofile…d27a) ! You connected the dots for me.