The people operating the repository want people to use it. They don't want them getting things from untrustworthy places. But if they can just prohibit that, they can be tyrants -- refusing beneficial software that the user wants because the monopoly provider has a conflict of interest or is being coerced by someone else.
By contrast, if the user can load the beneficial application themselves then the repository has the incentive to prevent that from happening (and thereby discourage users from doing that in general) by carrying it themselves. And the fact that there can be competing repositories means that the one that carries the most beneficial software and the least user-hostile software can be the one that wins in the marketplace. But not if the vendor locks everyone else out and becomes an abusive monopolist.
All the more reason to have a supported way to do it. If they require the malware to replace the Firefox binary with a different one, what happens when it does? The user ends up with twelve pieces of malware instead of one because the original malware author didn't bother to support browser updates properly and the user ends up with a browser full of publicly known security vulnerabilities.
> And then Linux is also niche enough as a consumer OS that it's just not as attractive for malware in the first place.
People have been claiming that as the reason there was so much more malware on Windows for decades. Then Windows adopted some of the same types of measures as Linux and the amount of Windows malware fell off considerably.