Fundamentally, malware is about deception. If the user understands what is being done and why (we're tracking everything we can, then selling that to everyone) then it's not malware. The typical adware hosted on FileZilla shows a screen in the middle of the install process with multiple paragraphs of text in a font smaller than everything else, which vaguely refers to ad supported software and a link to a privacy policy that nobody reads or understands.
I don't know if there's a legal definition of malware, that's definitely malware in my understanding of the word.