Do people even double check installers are digitally signed? There's so much open source stuff out there that is not digitally signed, most people might not even notice.
I use winget or homebrew, those tools do so for me and if something doesn't match they show an error.
Windows has displayed a big scary orange prompt for at least the last decade when it isn't. More like 15-20 years IIRC.
But I'm sure people blindly click through the "Unknown author" prompt just as they would ignore a certificate error.