18
Notepad++ updater installed malware
(www.heise.de)
This is a most excellent place for technology news and articles.
So the private key was left in the Github source code and nobody caught it? Or was it the public key? (which makes this statement way less impactful)
Private key probably. Only the public key is not enough to sign the package.