They wrote a commit message with Nat Friedman's email address using a design feature of git, but it was still a design feature of GitHub that took this non-gpg signed commit and linked it with Nat Frieman's account, making it appear very legitimate in the GitHub UI, without an option for him to change that.