StrongPity: Advanced Persistent Threat
usa.kaspersky.com
usa.kaspersky.com
Malware explicitly targeting crypto software is scary regardless, however.
- putty.exe
- filezilla.exe
- winscp.exe
- mstsc.exe
- mRemoteNG.exe
The malware also has the capabilities to fetch new instructions, so there's no telling what happens when any particular software is detected.
[1] https://securelist.com/blog/research/76147/on-the-strongpity... (linked in the first line of this thread's article)
Of course chocolatey itself could be compromised.
Edge has Microsoft SmartScreen[1], Chrome has CAMP[2] / Safe Browsing and Firefox has a system that also uses Google's data[3].
[1] https://technet.microsoft.com/en-us/itpro/microsoft-edge/sec...
[2] https://www.cs.jhu.edu/~moheeb/aburajab-ndss-13.pdf
[3] https://wiki.mozilla.org/Security/Features/Application_Reput...
Edit: I missed that part where you were meant pro actively check against publisher provided signatures. The above systems do that only via looking at the code's embedded signature and indirectly via "wisdom of the crowds" style reputation.