As long as the "ROM" isn't actually an executable file (such as a .exe), you should be safe. Some shady websites will tell you that you're downloading a ROM, but are really downloading a malware installer, so you have to watch out. But as long as you're downloading an actual ROM file (the type of file is different for each console, but Google says that most PS2 ROMs should be a .ISO file), you're probably fine.
Disclaimer: there is always a risk when pirating files. Make sure you use an ad blocker and don't accidentally click on any fake download links.