Electron ASAR packages (used by WhatsApp, Skype, Slack) come with no integrity and authenticity controls, which makes them an easy target for malicious modification. Same problem with #appimage on Linux by the way. https://arstechnica.com/information-technology/2019/08/skype-slack-other-electron-based-apps-can-be-easily-backdoored/