But why not? This is not some complex exploit, just standard JavaScript.
I saw the same attitude after the xcode backdoor. "There is no reason to believe any personal data has been affected", well if apple didn't even knew this thing existed how could they possibly know if it was activly used??
Edit: according to reddit apple just pulled all apps made by these guys. Not a proof of anything but still something to consider