So, McAfee identifies a single node as "associated" with the incident: li107-40[dot]members[dot]linode[dot]com. And Linode has a post which specifically references a single node being associated but under Google's control and not malicious control at all times.
Doesn't appear to me that there's any contradiction. There is no evidence that a Linode was used for anything malicious. There is evidence that a Linode was used.