I'm not an OS guy either, but the article is setting off my baloney detector.
There's nothing inherent in OOP which is going to make it magically secure. It just seems like a spurious fact about OS/400 (and I say that as someone with very little knowledge of it, although I did use it as an 8 year old). Moreover, (maybe) there's no public record of infected instances, but that doesn't mean it didn't happen.