Your concerns are absolutely valid. Without casting any judgement on this project, the process of taking, modifying, and redistributing is hard to do in a trustworthy way. Big companies go to extreme lengths to ensure a chain of trust of the software they build, and app distribution platforms[^1] go to extreme lengths to ensure a full chain of trust end-to-end[^2] from developer to apps running on users devices.
There's basically no way to do this without trusting the redistributor in addition to the original publisher, but some things can reduce the amount of trust. Having a verifiable build process, that checks signing keys and hashes, that re-signs, etc, that all helps. If end-users can theoretically produce exactly the same build themselves it's easier to trust it.
The best option however is for the source project to produce unbranded builds themselves, and potentially for a project like VSCodium to become "config only" for things like disabling telemetry, and therefore not requiring re-signing. The Chromium project distributes its own Chromium binaries which lack the Google-specific stuff for example.
[^1]: Mostly thinking of app stores, but the same is basically true of things like Debian package repositories.
[^2]: App stores typically re-sign in the middle, so you do have to trust the store, but see (1), these companies go to great lengths to ensure trustworthiness there.