There has been a number of cases of installers from trusted developers being infected lately. (For example Transmission being infected twice...) On our side (developers) we need to be careful with this idea that "we will know" when something is wrong and be more careful when deploying software. It would also be nice if some form of tool could be used to test a binary to make sure it only contains what it should conta…
I suggest you use something like "Little Snitch" for mac which warns you when software makes inside/outside connections.
It might not be the best, but it's definitely something that works to mitigate some hacks.