For me the egregious thing isn't malware in actual downloads, it's the ads with fake 'click here to download' buttons that try to shovel you malware. They have a lot more control over ads than they do over individual projects, and this suggests a disturbing level of not-giving-a-shit.

