I’m reading James Bamford’s new book on counterintelligence failures, Spyfail. It’s okay so far, but I would think any kind of technical review would have addressed this: I think it’s a significant error to equate an exploit to a virus/worm that uses it.
Again, this is not how the exploit worked. It didn’t auto-spread, and it certainly didn’t have any ransomware functionality built into it. This was all added by others after the release.