

Sort of. The program uses a specific part of the website for its auto update. And it also didn’t do any kinds of TLS (https) validation (which would prevent changing the destination). They also signed their installers (which would throw an error if the file had been modified) but the auto update didn’t check for a valid signature. So basically the two big things that a browser would do when you visit the site to download the installer, the auto updater just… Wasn’t doing.
So people who visited the site to manually download the installer were fine. They would have been alerted if the TLS cert was invalid or if the installer wasn’t properly signed. But if you used the auto updater, you wouldn’t get any of those errors and it would happily install the malware.


Also worth noting that Costco doesn’t require a membership for their fresh food, pharmacy, or (depending on where you live, and your local liquor laws) liquor store. You can just tell the greeter that you’re there for the pizza, and they’ll wave you through.
Their pharmacy is often one of the cheapest, and the pharmacy techs at my local Costco are all super helpful. Apparently working in pharmacies is pretty soul-sucking, but my local employees always seem to be in a good (and not just artificial “retail smile” good) mood.
And yes, the Costco brand vodka is every bit as good as Grey Goose.