You and I wouldn't spend 20 man-years and $50 million to do that, but our government definitely would if there were a chance to, say, disrupt Iran's nuclear ambitions for a few months.
It is yet another clever way to extract information and I expect to see CPU coolers with ferrite flux redirectors to appear at some point to counter it.
I've never seen a SCIF where going in after hours is the "easy route". They're full of motion detectors and the entrance is typically a heavy metal door with a combination lock. The air ducts are too small to crawl through. :)
Well, the whole point is that it is supposedly a "secure" facility, so you may have the rare occasion to enter it again, after having beeen exceptionally been able to access it once to install the software (since you cannot install it remotely due to the air gap and faraday cage even if you can get access and by-pass firewalls and/or data-diodes) and deploy the receiver with flash under the floor (no pictures are allowed on walls of a "secure" facility, and someone may notice a fresh patch of plaster on the wall[1]), in order to gather the data next year, on the 4th of July, not exactly "in a timely fashion".
[1] And no, it is not like any "secure" facility is confining with an easily accessible area, the walls are normally reinforced concrete and with no less than 30-40 cm thickness.
It's not the first time things like this have happened http://www.cryptomuseum.com/covert/bugs/selectric/index.htm
Because "bugs" that transmit are susceptible to being sniffed by RF signal detectors, opponents would disguise devices which could record their environment, and figure out ways to 'leave' them in places of interest and recover them later.
Because I've not been in a SCIF I don't know if it gets janitorial service or any regular maintenance at all but if it did, then that might be how this might work.
Mostly I was responding to the challenge of "it's only 100cm and you can't transmit anyway" assertion that the vulnerability was not exploitable. I'm expect someone could figure out how to exploit it.
Well, several years ago I have actually built a couple of them (actually something very similar to them, the term SCIF is US) for the military here in Italy.
Though admittedly not - at least from the construction specs - to be used for this kind of air-gapped computing, they were either a "safe conference room" or a (very large) "storing safe" (to store paper documents and/or weapons).
I have no idea which security measures/protocols were later employed to limit access to them, of course, but there were a number of safety features that would make physical access by any means seemingly impossible.
Of course if you could impersonate someone else authorized or if you can bribe someone with legitimate access, than any construction/safety measure would be m00t, but then if you can obtain that kind of access it would be easier to simply get the data from the computer.
http://www.primalunleashed.com/intel/SCIF.htm (seems to be from a videogame)
https://scifglobal.com/ (looks like a contractor that builds the things)
Janitorial service, etc are usually limited to a sign telling whoever works there to take out their own trash and clean up their own spilled coffee. Everything else (like changing a light-bulb) is done in accordance with procedures specifically designed to make it damn near impossible for a single person to do anything they shouldn't.
Of course, people still had to be repeatedly counseled for plugging the same USB flash drives from personal movies/internet/etc systems into red (S) and orange (TS) systems. It was sad.
Realistically security countermeasures adapt to the likely threats. In Iraq and Afghanistan the technical sophistication of the adversary in terms of SIGINT/ELINT was poor, so they rightly decided giving up security for wider distribution of information with friendly forces was the right call.