It would be impossible for this to be the attack vector used.
While these credentials let you push things to the download servers, the actual malware was inserted much earlier during the build process before the code was signed.
While these credentials let you push things to the download servers, the actual malware was inserted much earlier during the build process before the code was signed.