Securing a server is hard for the average user. But in any case LastPass uses E2EE so if the password was compromised that's most likely on client side, and for this self-hosted or not would make no difference.
Mainly with compromised\rogue updates, you push a malicious update to customers and then get access without needing to compromise the hosts.
Very similar to a supply-chain attack.