Isn't Clam AV open source? That makes me nervous since the "bad guys" can get their hands on the AV source code.

that is an old argument that was debunked a very long time ago.
that was one of the original topics in a FUD campain that Microsoft started.
seriously, the reason why the GNU applications & the Linux kernel are more secure is because of the open source philosophy. the code is thoroughly scrutinized by many OSS programmers, Distribution maintainers, CERT, CERN, and others. if there is a security issue, a fix is usually available within hours, if not within a couple of days. GNU software usually is a "labor of love", & the programmers who write it usually use good coding practices. i am not saying that open source software is perfect, it is not, but it is of much higher quality than a lot of the software for Microsoft Windows including Windows itself.
one example of this is look at all of the reported compromises & infections on the internet, the vast majority of them are ether consumer PC's running Microsoft Windows or some business running Microsoft IIS server.
another favorite thing that the Microsoft trolls bring up (i am not talking about you, Monkeypox), & has been debunked over and over again is the phrase "Microsoft is attacked more because of their marketshare".
that is far from the truth. believe it or not, there are more Linux servers on the internet than Microsoft. in the Hax00r community, a "captured" Linux server is worth more then a army of botnetted Windows machines. it is also said that the cracker who captures it would be elevated to l33t status. it is very hard (if not impossible) to crack into a properly configured Linux server. it is even harder to crack into a Linux Desktop that is properly configured.