The download server of the torrent client Transmission was hacked and a malicious version of the client was uploaded. The malicious copy of the software was signed using a legitimate certificate (which appears to be stolen from the Apple developer program).
The publishing infrastructure was affected, plus a developer certificate (by someone not associated with Transmission) was used to sign and allow for a legitimate-looking installation