This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., an independent security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account.