It is definitely a false alarm. The site has not been hacked and those are the original files. I have scanned all those files locally with Defender and NOD32. I scanned both the installers and the installed versions.
This morning I downloaded them from the site again and rescanned them. Nothing. I then uploaded 2.2.3.8 to Virus Total. Here is the report:
https://www.virustotal.com/#/file/c7d8512b096ad7c564c203bef0712548aeb192d2c9e7d712d77abd67f8e06768/detectionI also downloaded 2.2.3.8B and uploaded it to virus total and here is that report:
https://www.virustotal.com/#/file/47c16a2e1359df073000e8bc7e53904e47a729f06ff3b234d3ec71b7c97d360d/detectionThen I enabled Windows defender's cloud based submission and analysis and it would not let me download the file. So there is something new in that system is generating the false positive. Either that or Windows defender got it right and all other anti-virus programs on the planet got it wrong...
Also of note is that even when I have windows defender's cloud system enabled, it only blocks the file from being downloaded. If the file is already downloaded and then you scan it (either the installer or the folder after install) it finds zero threats.
I can see I'm in for some fun trying to get them to fix this...