Sigh.. This could be somewhat repaired by making a beta-release, distributing to devs and testers. Once confirmed good, rename file and release via IPFS. The key here, is if multiple devs did this, the hashsum would prove the file being shared.
Any one client that's been hacked or infected would show up as an improper hash and easily spotted.
Any one client that's been hacked or infected would show up as an improper hash and easily spotted.