You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.
>You can't trust anybody except for open source repositories. That is patently false. Established profitable companies in a market with multiple competitors usually do not fuck with their customers, if they charge up-front for their product/service. On the other hand, companies that give away stuff for "free" have to find unique ways to pay the bills (be it hosting fees, or hardware costs, or developer time, etc). In…
I've actually never seen an an freedom respecting project that included adware, and I can confidently say that the reason for that is that if a team were to do that, somebody would fork the repo and remove the offensive junk. As long as it gets caught, it's a self healing ecosystem. The same cannot be said for non-free software, as the pool of people who could find junk is so much smaller, but also because if junk were to be found by an employee, they'd have very little power to actually do anything about it.
Open source is volunteers, and when its not, they run on donations. When the donations stop, they stop. Some have found clever ways to make money, such as pay4premium or pay4support, but I've never seen ad injectors. Those come from third party distributors who aren't affiliated with the projects and can be avoided.