How is this a scam?

There’s a scam that involves an email pitch similar to that received by the OP, with either a malware laden link or attached file included. The email will say something like “Thanks for your order. $$ will be charged to your card. Click below to cancel”.

There was a link to “View Your Order”. I stopped my wife as she was about to click on it. However, the charge actually showed up on our CC account as a pending, so I don’t think it was a malware gambit.