OP mostly FUD but good that people are aware of all the attack vectors.
Can't be too careful when it comes to large amounts of money.
If you are using electrum, I have published several utility
scripts in the electrum sub forum that you can use
to verify if the addresses and keys from your copy
of electrum are legit.
how can normal people use such script?

the normal people wants something safe and simple.
it was proved that the COLD wallet can be hacked. once you are hacked, you cannot recover the bitcoin.