if you were advertising a phisher program that emailed the info, then someone could have decompiled it and viewed the sent inbox of the email that sends the info (since the credentials are in the code) and if you tested the program to see if it works then your info would be in the sent inbox and since everyone who is even doing that pretty much decompiled mine and stole my source code, i made it so it views the whole entire accounts.js if user has muledump downloaded.
Luis is in fact one of the people who was advertising a phisher but if you didnt download anything than it obviously couldnt have been him, but if you yourself were advertising one, anyone could have decompield it and stole your shit.