The 'malware' used a Windows misfeature that allows the BIOS to supply an executable that is run during startup. So the malware was in the firmware but only runs on Windows.
This should really only affect Windows systems as far as I know -- Windows is running an executable stored in the firmware at boot (a rather dubious feature, in my opinion, but it's intended as an anti-theft measure). Lenovo used that feature to try to circumvent removal of their crapware when someone reinstalls the OS.
For example SMM (system management mode) code is certainly loaded and executed under any operating system. You have to just trust the mainboard vendor.
It gets copied from the firmware and runs pre OS. But the executable only runs on windows from what I can tell, so its technically its cross platform but it wont run on both platforms.