Hacker News new | ask | show | jobs
by okket 3579 days ago
You were only at risk when downloaded fresh copies from the website. Updates were checked by the already installed Transmission.
1 comments

Except that time where the auto update mechanism was actually distributing a hacked version

http://www.macrumors.com/2016/03/07/transmission-malware-dow...

No it did not. They distributed a new version via the build-in updater to try to remove the malware from the copies downloaded from the website. Sparkle use a digital signature and the malware author did not have the private key to create a valid signature for the update. So even if a malware was downloaded, Transmission would report a "invalid archive downloaded" error.