hopefully nobody adds a cargo-buidl package then!
It's not like a tool like npx which will allow you to invoke code in arbitrary packages.
Typosquatting is definitely an issue, but not in this specific case.
Security story of developing on Linux is basically non-existent unless you do everything on a remote machine or at least in a container (and, oh irony: direct access from your user to the Docker daemon basically means having root for that user).
But with build scripts (build.rs) any crate indeed has arbitrary code execution at build time, so they can't be trusted, like you imply.
However, sandboxing might be coming for build scripts, and when that's done, the typo attack is still there (package "foo" installing cargo-buidl).