> SmartTube’s developer told me that the computer used to create the APKs for the project’s official GitHub page was compromised by malware. As a result, some official SmartTube releases were unintentionally released with malware. Seems it's lacking in information about how a malware manages to compromise supposedly signed releases? Do authors not have the production signing keys behind a password or similar, and rev…
the malware need not actively create a release like a worm, it can just infect every build and if you don't check carefully, your next regular release will contain it.
maybe QA will find it... but they're testing X number of JIRA tickets based on Y epics and if it's not on the list they're not looking...