A major point of the article is that there's nothing unique about curl-to-shell which enables this exploit; it would be equally easy to perform it with a fully-signed and checksummed binary downloaded through a secure channel.
https://sysdig.com/blog/friends-dont-let-friends-curl-bash/
https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b...
These attacks can be mounted on the network side.
Also you can inadvertently execute data from a benign captive portal or a server error page and so on.