You need to be careful with executables, that's true, but
Signed GOG installer? That'll be fine.
File checksum matches known scene release? That'll be fine.
I've heard of more people getting infected via Steam than by torrent downloads recently (see: Slay the Spire on Christmas day).