Linux package managers (the normal way to install software) use signed packages.

I don't know how easy/hard it would be to compromise that.