I think they mean using curl to grab something and piping the output to bash so it it executed locally.
And it is pretty common. Things like ohmyzsh use it. I find it scary because you’re running things direct from the web without any package signature architecture. I would trust the omz people but what if their GitHub was compromised? But don’t check any of the source? No. I don’t anyway, but with a bit of fear :/













Shuffalo, 2m 08s
🟡🟡🟡🟡 🟡🟡🟡🟡🟡 🟡🟡🟡🟡🟡🟡 🟡🟡🟡🟡🟡🟡🟡 🟡🟡🟡🟡🟡🟡🟡🟡 🤩🤩🤩🤩🤩🤩🤩🤩🤩
https://www.newyorker.com/puzzles-and-games-dept/shuffalo/2025/11/16