Yes, you're right - I've done some more research on the github site, and figured out how they do it. The burner image can be sent to RAM over USB, to cause the microcontroller to boot from it. Then, that burner is used to flash the malicous firmware image.