Can you please explain it a little bit more? I am just curious.
Calling it "secret", as the article does, seems disingenous. (Further, even if somebody downloads an application in an incog window, it is probably better for the system's security posture to record these xattrs for such a "hey, is this what you actually meant to download and execute?" situation.)
Like, if you are going to Have Opinions about something like this--you are of the temperament to care (which is a way of saying "I don't and you probably shouldn't either, tbh, encrypt your drive if you're that geeked up about it")--you should probably know.
xattr -p com.apple.metadata:kMDItemWhereFroms <file downloaded with chrome> | xxd -r -p | plutil -convert json -o - - | jq "."
And one can catalog the sources of downloads made with Chrome.