Perhaps the app was not compromised, to begin with. Hackers might’ve gotten into the build infrastructure of the app, rewrote it to make it compromised, and then all the users of that app are now compromised.
Lesson: ask your (in this case Microsoft) employees to not use work computers for any personal use.
/me goes to check if my password manager company uses Okta.