The article specifically mentions that the methodology here is to trick users into running an obfuscated CLI command…that downloads and runs a binary
In this case, the user is warned that the command wants to do something dangerous and must manually allow or deny the action.