Filezilla bug report on how they embraced shipping malware five years ago: https://trac.filezilla-project.org/ticket/8888
Blog post from sourceforge during the "dark times" where they announced they were partnering with teams like Filezilla to ship you malware: https://sourceforge.net/blog/today-we-offer-devshare-beta-a-sustainable-way-to-fund-open-source-software/
Sourceforce ended this practice in 2016. Filezilla's devs want to keep it going: https://forum.filezilla-project.org/viewtopic.php?t=48441