That is one of the many reasons why DEB packages should be required to have embedded GPG signature of a packager