Sure. "don't use Kazakhfox, it's malware, we've submitted definitions to the AV databases" isn't a hard sell for your 99%+ audience.
Malware forks of open source projects (and closed-source software!) are not a new problem.
Malware forks of open source projects (and closed-source software!) are not a new problem.
In reality, being one BGP trick away from a mere dedicated individual or corporate owning certs for your domain is an actual risk today.