that can be a way yes, malware just alters the bootloader so it always loads on boot and goes undetected by antivirus scanners, and sits on your computer, either logging everything you do, or punches holes in your network to allow bad actors to infiltrate
you gotta go out of your way to install malware, the only way you can download anything bad is randomly downloading stuff from shady websites, or if official repos would be compromised, which i think they have contingencies for anyway
the shadiest thing you can do on linux is install random things off the AUR tbh, on bazzite you need distrobox for that. The only thing distrobox would have access to is your home dir, not sure if it can even get your /usr directory, i don't think so
on Bazzite you get selinux out of the box too, which is one more layer to protect yourself, if all you do is download and play games from reputable places and keep your system up to date, there's nothing to worry about, just follow best safe practices