This is not really in the wild or even the "wild" by any reasonable definition:
1. The exploit isn't by a real attacker. It comes from a pen-testing firm (white hats).
2. It was patched years ago, probably written years ago. Article doesn't say what happens when the kernel is newer than 2018 but presumably, it doesn't work? Spectre is still relevant for programs sandboxing code within themselves like browsers, but for normal patched systems, it doesn't seem to matter.
3. There are still no known cases of real attackers using Spectre, even though we have just seen an attack that Microsoft claimed may have had more than 1000 developers working on it (the Solar Winds supply chain attack). Spectre just doesn't seem like a very interesting way in for attackers compared to other types of vulnerability.