Yes, people should download and burn from a clean computer, but I have yet to hear of a virus that can embed itself in a data image in a form that could ever be executed.
Remember, the .IMG file is a huge non-executable of random bits until it’s booted.
If you’re creating a bootable disk, and if a virus vector is via the boot sector, and if you’re creating that bootable disk from such an infected machine...
Sure we can pay the probabilities of all such variables being true, but it’s just better practice to have a disk created from a known clean machine. That helps to remove nagging doubts. Users creating such a disk, just once a year, will cover it.
My $0.02