There isn't any malware when downloading from
http://www.oracle.com/technetwork/java/javase/downloads/inde...
Or when packaging the Java application with the runtime
http://docs.oracle.com/javase/8/docs/technotes/tools/windows...
Or using one of the commercial JVMs that compile Java to native code
Or just bothering to read the dialog when installing it from Java.com.
While it is true the bundling shouldn't exist in the first place, any knowledgeable Java developer knows how to get applications deployed without it being an issue.
Actually my biggest problem with Java is Google dragging its feets and making the Android fragmentation a return of the J2ME headaches. Sun and Oracle were right all along.