From what I am understanding, it was a 40 minute window when the malicious model was available to download in the repositories. After it was downloaded, they had all the time until it was detected in the organization to exfiltrate the data, which was potentially weeks or months.

Skysurfer
@Skysurfer@slrpnk.net · Joined Jun 2025