Let's be real, in most cases it is:
curl -s script.random-guy.net | sh
It is such glaring security hole that there was an old submission about filling such install script with `sleep` commands and detecting it on server side, to send different versions for downloading (and reviewing) and for actual direct execution.I use those scripts to improve the likelyhood it'll fail to do anything useful.
I even used uname as a fuzzing tool, and that broke builds spectacularly. There's now a more reasonable uname in the sandbox for builds.
the method you describe is clearly only done by people that are irresponsible and most probably stupid.
and no, this is not how most software is installed