Companion to the malware piece. This focuses specifically on red flags.
Distribution red flags
Hosted on a site you've never heard of. No version history. No author profile. Comments disabled. Discord invite required to download.
These don't all mean malware but they shift the risk calculus.
Bundle red flags
Installer .exe required. Files outside the game folder. Antivirus warnings on download. Unusual file sizes.
Behaviour red flags
After install: browser hijacks, unexplained processes, unusual disk activity, request for elevated permissions you didn't expect.