The writeup says it right there:
"The security exper’s analysis indicates the attack ceased on November 10, 2025, while the hosting provider’s statement shows potential attacker access until December 2, 2025. Based on both assessment, I estimate the overall compromise period spanned from June through December 2, 2025, when all attacker access was definitively terminated."
Yeah, that refers to the MITM attack on the update server. We have no fucking clue what they actually did while they were in the middle - whatever exploit code was running may very well be running right now on compromised machines. Nobody knows what the compromised exes actually did.
Thanks for your nonanswer, though. It was about as unhelpful and unspecific as the original blogpost for this.