Files and path names listed in the "Malicious files" section in the blog post https://circleci.com/blog/jan-4-2023-incident-report/ lead me to believe that it is MacOS.
Malicious files to search for and remove:
/private/tmp/.svx856.log /private/tmp/.ptslog PTX-Player.dmg (SHA256: 8913e38592228adc067d82f66c150d87004ec946e579d4a00c53b61444ff35bf) PTX.app