Sounds like they logged passwords in plaintext. I seriously doubt that was done intentionally.
I think every developer has some idea how this could have happened.
Someone is working on a bug. "I'll print this state out to console and remove before committing." Forgets to remove it and does git add *. Its overlooked in code review and is then pushed to prod. Once running, the stdout of the process is automatically shipped to some log database. And just like that, there are now passwords in plaintext in the log database.
Sloppy as hell? Sure. Malicious? Highly unlikely.