If your users download WinSCP from our official download page only, you are safe.
Ideally you should verify a file checksum after the download.

Malicious Putty - possible security issue?

it has come to my attention that there is malware infected version of PuTTY out there ( and since WinSCP is based on PuTTY, I'd like to ask if there is any possibility that similar version of WinSCP appears. Users of our servers are using WinSCP a lot and this might be big security problem. Thanks in advance for any information!