@lcamtuflcamtuf
Yep, and the developer doesn't even need to get hacked, there's a years-long history of bad actors buying control of legitimate mobile apps, browser extensions, wordpress plugins etc and pushing updates with malware
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/reedmideke/statuses/115999288406954929 on your instance and quote it. (Note that quoting is not supported in Mastodon.)