The name that keeps coming up is Jia Tan (https://github.com/JiaT75/) but we have no way of knowing if this is a real name, pseudonym, or even a collective of people.
Given the sophistication of this attack it would indeed be downright negligent to presume that it's the attackers' legal name and that they have zero OPSEC.
1) Probably by design protonmail doesn't keep these kinds of logs around for very long
2) Hacking groups pretty much always proxy their connection through multiple layers of machines they've rooted, making it very difficult or impossible to actually trace back to the original IP
It's also worth pointing out, given the almost two years of seemingly valuable contribution, that this could be a real person who was compromised or coerced into pushing the exploit.
Were they? The attacker has had commit rights for 1.5 years or so, but my understanding is that all the exploit components were recent commits. Is that wrong?