The sysadmins at my job frequently find malware artifacts on our servers, because we exclusively use Windows server. And the expectation is you RDP in to get stuff done, which means there's a big potential for human failure.
Also most Windows software is just taken off the web and installed with administrator privileges. Sure, there are package managers. In practice, they're rarely used on Windows.
From a technical standpoint, Windows isn't "that bad" at allowing malware. From a culture standpoint, almost nothing has changed since the 90s. Linux and Mac have a different culture.