On windows they modify the PE header of the exe, and adds extra information to a certificate table at the end of the file, without affecting the signature of the file. (Last 4 bytes of the file gives the size of the payload, giving you the offset to start reading a string that starts with OPR followed by a base64 encoded string, which contains a checksum and a json object. The json object contains country of origin, http_referrer of the download, a timestamp, UTM-parameters seen on the referrer, the user agent and a uuid assigned to the download. This uuid is kept for the life time of the browser install.)
On mac, the process is a bit different, but there they use appledouble (._-meta files) to modify the zip-file on the fly while downloading including the same type of data.