The vector is going to be Deem's website, that launched a man-in-the middle attack on anyone who used the Patreon log-in button, and harvested Patreon passwords, and who knows what else. I know that MY Patreon account had several unauthorized log-in attempts. A committed hacker is probably looking to get access to Deem's Patreon and redirect payments to the hacker. If Deem was sloppy about security on his home network, like using the same password everywhere, I have no doubt that hacker compromised his stuff.
I was, that's when I switched to last pass and put different 16 character pws and 2FA on everything. After which I got the fake Last Pass email, presumably from the hacker. For a week I had been scanning my machine with Kasperky, Malware Bytes, Hitman Pro, and Windows Defender (lol). I had LP pro, including the application PW locker which presumably stores your master password encrypted somewhere on your HD. After the hacker was in my system I started getting random 2FA notices from Last Pass. Once I even accidentally hit the thumbprint, but fortunately I had both the thumbprint and keycode enabled.
My router security had previously never even occurred to me, but a hard reset on it didn't work after the attack. I reinstalled the firmware, spent a few hours setting up rules, and a few minutes after I put it online the routers access IP and login/pw had been changed. Obviously, I have a new router now.
Since it's been clean(I hope) I've also scanned it with with every root kit scanner available and they've found nothing. So hopefully it is actually clean.