The key was the app’s, the data was the merchant’s, and the shopper had never heard of either. The party that knows how it was stolen has not spoken.
The API served the request as it would any other. The credential came from a vendor’s environment, and the vendor is the one party nobody has named.
A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.