The main issue is that he doesn't communicate much. For years people have reported issues on GitHub, he hasn't interacted at all with them, but they get quietly fixed in the next release. That was fine until this happened, and people were scrambling to find malware-free versions, and looking for updates.
He put out a statement saying he would publish a new version with a new signing key, and at that time explain exactly what happened. So far there has been a beta with the new key, and no other updates, which is pretty much how he has always done things.
To make matters worse, people on Reddit and on Github have been pointing to versions they claim are not infected, but with little evidence beyond maybe a VirusTotal scan. Given the lack of information from the developer, it is unwise to trust them.
It's a shame because SmartTube is one of the best apps ever. YouTube, with ad blocking, SponsorBlock (skips over in-video ads), and DeArrow (replaced clickbait thumbnails and video titles with descriptive ones), and many quality of life features like disabling auto-translation and having easy access to playing videos incognito.
Hopefully it recovers quickly. Normally he gets updates out within days or even hours when YouTube breaks something, and it's been several days already.