The fact that the binary was infected, I can somewhat understand. However, the way communication happened/is happening on this issue is very disconcerning and basically makes it impossible to know whether it's safe to currently download 2.92 from their site. Questions like - how did the compromised binary get there? Was the source code hijacked or was the binary altered after it had been built? - Were the SHA256 hash…
Although I'm not a Transmission developer, I develop software that uses the same automatic update mechanism. It appears that the hacker did not update the MD5 present in the automatic update mechanism. (Sparkle) Thus, when the automatic update mechanism downloaded the hacked version of Transmission, it reported it as a corrupted download.
You can see the comment here: https://forum.transmissionbt.com/viewtopic.php?f=4&t=17834#p...