Any malicious software would need to get access to the file system. OS X requires that you type in your user name and password for anything like this. So malware such as viruses, Trojans, and worms would need you to install and authorize them. So just being aware of what your downloading and installing is really all you need to do.