True, but malicious people often put their malicious programs in DMG files. If you are downloading something like a movie (obviously not supposed to be a program), and you double click on the DMG file and it wants to install, you can almost certainly guarantee that you have downloaded malware - do not proceed with the install.