Rings a bell, I think it was because Curl showed up as the user agent for malicious activity.
You have to be kind of lost to contact Daniel about it, but I think it's ok behaviour for junior sysadmins that are just starting out, everyone was starting out sometime, and curl is like a lightning catcher for the world's daily lucky thousand.
It's because curl is often embedded as a library or standalone executable with other software. So when a malicious or compromised piece of software is found, a less experienced investigator might see curl with its author tags in the file metadata, and follow it back to upstream.