A few years back, Handbrake (an open-source video encoder) had their download server compromised and the Mac package replaced with a trojan. It was after that happened that I started verifying the file hashes even if the file comes from a trusted source.
|