Your concerns are valid.
In my opinion the easiest solution, if you don’t know what youre doing (or dont wanna care) would be to use exclusively an immutable distro. That would lock you out of tweaking the system, but also heavily limit any potential malware. This should be sufficient imo:
- keep system up to date
- dont run programs or commands from unofficial channels
- have firewall enabled and running
- make offline backups of user files
- use immutable distro