The OS installation images come from Microsoft. They're the same amount of malware as the OS that comes preinstalled on your laptop. Probably a tad less, depending on the brand.
So instead of downloading the OS, you're downloading a patching executable? How do you trust this? Is it open source and auditable? Otherwise you're opening yourself up to the same concerns.
Probably that one of the original comments on this thread suggested using another free and open source thing instead of using this free and open source thing? Why is linux exempt from "it comes with free malware" and not this other widely trusted and used tool?
Linux is more trusted because there are legions of cybersecurity experts who made their bones combing through the linux codebase to find security exploits. Even if this is open source, how can I be sure someone has audited it?
Alternatively I could pay what is, for me, a pittance, and know that my OS is not compromised.
The OS installation images come from Microsoft. They're the same amount of malware as the OS that comes preinstalled on your laptop. Probably a tad less, depending on the brand.