This sounds like the ‘this virus evades detection by hiding in a jpeg, until you manually extract it using this tool!’ stories we got 10 years ago.
I think there were cases where that was used to bypass some naive upload filters in conjunction with a back end that would detect and try to handle the attached/hidden malware.