Yes, sounds like scammers to me. I suggest changing your password on your Roku account as well as setting up a pin to prevent accidental or unauthorized purchases. If you have unknown charges on your credit card/bank card, I suggest contacting them as well.
I would think it is possible that someone can remotely install malware into a Roku device like any other device. If it were me, I would also factory reset the device and set it up as a new one, just in case.