Okay... but when "you" is a junior engineer on your team and now you are suddenly spending your entire weekend dealing with malware, it's kinda on you as well.
Downloading this attachement doesn't executes it. Checking out a branch in this case executes the file in the branch. Thats a big difference.
In this case, if you just run a git command yourself it executes the file as well.
On windows I guess?
On Linux and MacOS you'd need to run ./git to execute a malicious binary in the cloned repo.