Because, instead of "trusting" the update (or rather codebase) of a messenger, we now have to trust the complete browser bundle.
You may additionally ask why Electron, but that's a different question after all.
And all of that is completely out of your control and competence budget, unless you’re fine with shipping your first 50kb updates ten (metaphorical) years later.
Signal desktop doesn't use incremental updates. Each "update" is just reinstalling the whole package. That's what those 100 MB are.
It's possible to make incremental updates with binary patches, but it's more difficult. I guess Signal have other priorities.
What really grinds my gears is updates that intentionally break things. Sometimes on purpose, sometimes out of incompetence, but most often out of not giving a single fuck about backwards compatibility or the surrounding ecosystem.
Every few years I lull myself into the false sense of security over running apt upgrade, until it finally destroys one of my installs yet again. Naturally only one previous package is ever stored, so a revert is impossible if you ever spent more than two releases not doing an upgrade. Asshole-ass design. Don't get me started on Windows updates (actual malware) or new python versions...
Generally speaking, I agree, the npm-ecosystem still has this pervasive problem that pulling one package can result in many transitive dependencies, but a growing amount of well-known packages try to keep it as limited as possible. Looking at the transitive dependency graph is definitely good (necessary) hygiene when picking dependencies, and when done rigorously enough, there shouldn't be too many bad surprises, at least in my personal experience.
The fastest way to money is to not dig too deep
Or Tesla.