I'm not sure if you could actually get criminal charges for this unless you were hosting the malware in which case that's another issue. It would essentially be the same as walking around with a website URL on your shirt. The observer is responsible for typing in the URL or scanning the code and what they decide to do on the website that follows.
Consider florida, where if you are caught with shrooms that are wet, freshly picked, they cannot convict you for carrying contraband because you do not necessarily know what you picked.
Laws are often based on intent. In some cases, penalties vary depending on intent. It would be an unacceptably brutally harsh law to judge someone under a presumption of harmful intent for something they might have no awareness of.
QR codes can have icons on them. Certainly if I created such a t-shirt, I would put some cool looking icon in the center of it. Someone being dragged through the system might argue “i did not know that qr code was real.. i just liked the cat in the middle of it”.
I tend to agree that this is how it should be, that doesn't mean that's how it is. If you walk around with a T-shirt that says "kill all CEOs" along with where to find them, you're going to run into some trouble, despite being a similar situation- you're just giving instructions, it's up to the viewer what to do with them.
Except the shirt doesn't say "visit this site, there are cool things on it". If you're gonna make the comparison to CEOs then it would be like putting a CEOs address on your shirt.
Not if it incites violence, causes harm or any of the other carve outs in the first amendment of the USA.
I am aware that the post is supposed to be funny, and you are most likely making a joke, but this is the internet and these sort of disclaimers tend to be necessary.
A smart attack would be coupled with a clear message. Have the malware clobber them with anti-evil messages and just like that you have a sound free speech defense.
Can we just get a website that plays a soundbite at full volume screaming about how they person is bad at privacy practices, maybe with Korn in the background for maximum embarrassment?