Earlier quoted context omitted.
I thought that too, but it doesn't apply. This is malware. It doesn't need someone to be gullible beyond the click of the button. Scams, on the other hand, require actually convincing the mark to send money, which is why they need to be sure they have a gullible person on the hook.
It's their button, why would they need the user to click it? I guess it could be clickjacking, but there must be an easier way to do that.
Because Javascript is allowed to do more, like show popup windows, if it happens in an onclick event of a button.