There's a potential downside too: If a trojan gets into the PPA sources, it will be automatically downloaded and installed by users.
Just something to keep in mind when adding a PPA: you're tying your machine's integrity to the integrity of the PPA and its keyholder(s), and this trust is tested each time you update your packages.
Apple does support code signatures for apps downloaded this way through their Developer ID program, but you have to pay $99/year to be a member of their developer program in order to do so.
In theory, you could still sign downloads using a code signing certificate you got elsewhere, but system wouldn't check it for you, and few people would bother to do it manually.
Hence, we have occurrences like the OP. The point is checking checksums or (better) signatures is the most common way to mitigate it. Otherwise, this will continue to happen. Dare I say that is the entire reason repo managers of all stripes do this in the first place.
[1] https://developer.apple.com/library/content/documentation/ID...