Software like https://github.com/google/santa can help, especially if you're doing IT in a large enterprise.
The feed used by the software's autoupdate framework(sparkle) was signed, so that would've prevented bad downloads through autoupdate.
Chrome for example has a sort of a bloom filter which is used to check all downloaded executables. This will raise a nasty warning if the thing you downloaded is not a "popular" download.
For obvious reason, this check is disabled for a bunch of sites, like github, sf, ...
I know for a fact that some malware authors host their stuff on GitHub exactly to bypass this Chrome check.
Here is theirs blog post introducing the feature in 2012: https://chrome.googleblog.com/2012/02/faster-browsing-safer-...
> Chrome also does checks on executable files (like ".exe" and ".msi" files). If the executable doesn't match a whitelist, Chrome checks with Google for more information, such as whether the website you're accessing hosts a high number of malicious downloads.
At the time I looked at the implementation in the Chrome source code, but I remember that it took me a while to locate it.