Ehhh, I would hesitate before blindly believing the claims you see on these repos. It's easy to say stuff like that in a README.md, and maybe at one point it was true, but these are literally thieves, so... take it with a grain of salt.
Especially considering the fact that there are discussions in the issues in these repos from the codeowners who "don't condone illegal activity" actively providing guidance on how to use the stolen data to login to victim's accounts on various services.