F-Droid does not contain malware. There were cases of maintainers going rogue, such as Simple apps being bought by an adware firm, which resulted in a timely takedown, directing users to a maintained fork Fossify. Like a distro repository, the user safety comes not from reactive moderation but active curation.
Meanwhile my parents are getting hammered by inescapable malvertisements from Google, a TTS voice ordering them to install a "cleaner" app or have their phone die, no matter how many you report or what knobs you touch under ad personalization. Facebook knew 20% of their yearly revenue was scams and intentionally deferred moderator action to keep that business. All this "trust" is so overwhelming, the only way to make our computing more trusted is if OEM auto-installed the malware themselves. Oh wait, Samsung does that!