Most of the users I know only get their software through their distros package manager. I think it would be quite tough to get malware in there, especially since most distros accept only free software.
The only thing preventing this from happening in Linux is a lack of interest by trojan writers (they could already do it with vmware workstation which is surely available on pirate sites and requires root privileges to install) and perhaps a lack of proprietary 3rd party software (which I'm sure a lot of people will say is a good thing, but that's another discussion).
Repo security is certainly very important. But well, ultimately you have to trust someone?
But I guess that there are two ways to feel really secure : either use openbsd, or just don't use the internet.