The obfuscated JavaScript was added to the end of the jQuery/Owl Carousel libraries and some other scripts on April 29th on the CASHU servers - and targeting jQuery and Owl Carousel libraries would also be a good attack-point.
Microsoft manually started flagging the scripts after I intentionally put them onto VirusTotal by the morning afterwards. It wasn't an existing detection such as through a generic signature they might have created for something else.
If all of this was genuinely a false positive, why wouldn't CASHU have had more information earlier on for everyone or an explanation as to why all of these issues occurred in the first place?