Sort:  

Encountered a strange pop-up on the computer. Dismissed it, and then the "download" sound from Finder was heard—like files being copied.

"That's odd," I thought. Then another pop-up appeared, showing all documents being duplicated to a folder in /tmp.

"What just happened?"

Ran a quick check, realizing there was remote access to the machine with a script copying files. Disconnected the internet instantly and did a thorough inspection. Found an osascript from the terminal moving files to Library/Caches, possibly for uploading.

No clue how it happened—could be due to auto-downloads from apps like Telegram or iMessage.

Desktop documents sync to iCloud and contain sensitive information. It's essential to stay vigilant because it's more of a 'when' than 'if' you'll be targeted.

Resorted to a full reset of the Mac and considering disabling iCloud syncing for documents.

Fortunately, no private keys are at risk since @vultisig manages security, even with iCloud storing a part of the vault shares.

Stay vigilant!