Speaking of supply-chain attacks like the one happened with .XZ compressor - we are taking this matter seriously. I recommend to download PgManage builds from the Github releases page https://github.com/commandprompt/pgmanage/releases Cheers!