Nothing can replace common sense and critical thinking when installing software from the internet. In the end, everything on the internet is potentially untrusted and blindly looking for ".com" is just a dumb strategy if your goal is not to get pwned.
I really cannot bring myself to consider not acquiring <software_name>.com a failure of the software package creator. As I said, if they are aware of a currently on-going phishing attempt that is masquerading as their own software, a prominent tip on their actual website would be nice.
The namespace is finite and not every website can be expected to be under .com. Also, the trustworthiness of a TLD is itself a fad, a fashion that changes over time. See: the popularity of .io.