He used retrohunt service which is part of virustotal https://virustotal.readme.io/docs/searching a service that allows developers to scan files for vulnerability. Apparently, virus total stores files and allows third parties to rescan these files later. Sounds like a vulnerability of this service and terrible practice. How can you expose your user files to any arbitrary access? Of course you should not put your secrets into file you upload to some virus scan, but how many users know that file they upload will be accessible publicly?