The software has to be distributed somehow, right? Probably over https? What makes curl more susceptible to MITM than apt-get/pip/gem/etc?
I don't particularly like curl | sh either, but without sudo, I'm not sure how much it /really/ differs, security wise, from other options.
Edit: real package managers have improved features compared to curl, as outlined in another branch of the comments.