Most of the users I know only get their software through their distros package manager. I think it would be quite tough to get malware in there, especially since most distros accept only free software.
The alleged botnet in the article here did not come through Apple or Adobe servers, it came through thepiratebay.org, demonoid, usenet, etc.. In other words, the safety of the official channels of distribution is largely irrelevant.
The only thing preventing this from happening in Linux is a lack of interest by trojan writers (they could already do it with vmware workstation which is surely available on pirate sites and requires root privileges to install) and perhaps a lack of proprietary 3rd party software (which I'm sure a lot of people will say is a good thing, but that's another discussion).