Earlier quoted context omitted.
I'm guessing a common sequence is someone knowing what curl is, but not knowing that Windows ships with it. So, thinking that System32\curl.exe must have been put there by malware, or put there by someone installing optional software.
Microsoft should have renamed it to WINDLHLP.COM or something Windowsy like that, and none of these people would have dared touch it.
C:\> alias curl
CommandType Name Version
Source
----------- ---- ------- ------
Alias curl -> Invoke-WebRequest