They explicitly mention that in the readme, its an apple security measure and you need to run that xattr command.
This is done in the name of "security", as if malware authors couldn't afford to pay it.
I think it's the identity verification bit that's dissuades malware authors, not the cost. Having your malware linked to your name and address isn't something most malware distributors want.
Nonprofit orgs and schools can get free dev accounts (at least for Apple), so for some open source projects distributed by one of the open source nonprofits, it is free.
I mean, the whole LastPass trojan situation seems to have proven that Apple doesn't even drill down on that: https://www.malwarebytes.com/blog/news/2024/02/warning-from-...