The malware includes a deadman switch that monitors whether your token has been revoked. If it detects revocation before you disable the monitoring service, it will destroy your home directory. You must disable the monitor service first, then rotate credentials second.