The distribution system you're describing exists and has been in use for decades. You just distribute the build using bittorrent.
And if someone invests in having >90% of the peers offer a malicious file and serve DHTs matching that file?
And if someone invests in having >90% of the peers offer a malicious file and serve DHTs matching that file?