In 2016 Super Micro Senior Vice President of Technology himself said Apple found "infected firmware." It was so bad that Apple "discontinued future business [with Super Micro] as a result of a compromised internal development environment". Strangely Apple at the time was denying the whole thing: https://appleinsider.com/articles/17/02/23/server-firmware-s... But today, 2 years later, in a statement denying the current spy chip saga, Apple now appears to acknowledge this 2016 security incident, while minimizing it: they say it was "an infected driver on a single Super Micro server in one of our labs" (https://www.apple.com/newsroom/2018/10/what-businessweek-got...)
Why would Apple deny then 2 years later confirm this security incident?
As usual, the truth is probably somewhere in the middle. It is very possible the anonymous sources at Apple who support the spy chip story are not technical persons and are confusing this 2016 incident with the spy chip incident (in fact it's what Apple theorizes in their statement.) It is very possible the spy chip does exist and was found at some companies, just not at Apple.
I also find it very interesting that the FBI, the one organization allegedly at the center of this saga investigating the spy chip, has remained completely silent, neither confirming nor denying the story.