It's because curl is often embedded as a library or standalone executable with other software. So when a malicious or compromised piece of software is found, a less experienced investigator might see curl with its author tags in the file metadata, and follow it back to upstream.