This is literally how code signing worked for Windows. Unsurprisingly signed malware has been far from uncommon
This model can work. It's just that microsoft is being sloppy.
Malware is very common on the Play store as well, signed software by one gatekeeper does not guarantee anything.