Doh!
Wonder who the three clients who received the signed malware were?
Crooks steal security firm’s crypto key, use it to sign malware | Ars Technica
Crooks steal security firm’s crypto key, use it to sign malware | Ars Technica