Its all about trust. No one wants to entrust their bitcoins to dodgy software.
Don't trust, verify!
Which is why, regardless of the fact that I always download Electrum from electrum.org... I will always verify the digital signature before installing and using it. I also always check the Electrum website on a semi-regular basis to look for updates.
In my opinion, Electrum isn't "dodgy"... and at the end of the day... the real blame lies at the feet of the scumbags executing these attacks.

verify what if he doesnt trust the developer?
Simple.. The source code.
Electrum is completely open source.
And if you don't trust the developer, simply check the whole code at github.
You only need to verify the source code once, then after each update you will simply be looking at the commits only to make sure no backdoor whatsoever has been built in.
You can even build it yourself from source if you don't want to download a prebuilt binary.