How is this the slightest bit different than faking a site and altering the binary/source package on the other end of a regular old Download link? (edit: Oh. You're doing user-agent sniffing for curl. Fair enough, but this still isn't any less secure than downloading and executing a binary.)
A good example of the fake downloads can be found with people running ads for VLC that link to their malware/adware invested versions (presumably, I've never actually bothered to investigate them).