Maybe you could use a known-good gpg on a a different system, to verify the gpg installer for MacOS (e.g if you have access to a Linux system where GPG is pre-installed; maybe install Linux in a ...