http://nksecur5aoxbew7x4t2jebk7ordomil3a4xubeamno76zexicppwhiad.onion
All accounts on the dirty OS must be treated as contaminated. All drives used for CP or used when logging into CP sites must be encrypted. That includes the system OS drive and storage drives. Use VeraCrypt or LUKS (Linux default). There is a lot of metadata generated, such as recently used files, thumbnail cache, system logs and program settings.