1) This problem was reported to Google a week ago, through multiple channels, by one of the app vendors who got ripped off: http://www.reddit.com/r/Android/comments/fvepu/someone_just_... Apparently, Google has an unofficial policy of ignoring copyright and trademark complaints, allowing lots of skeevy software to linger on the market.
2) The phone carriers are apparently very slow to patch root exploits.
3) Users should be able to trust everything in a curated app store, or else there's not much point to those 30% fees.
But a word of warning to iOS, WebOS, and Blackberry users:
4) Although the lax behavior of Google and the carriers made this exploit easier, we'll eventually see problems like this on most mobile platforms. Apple has allowed (benign) root exploits to slip through their approval process in the past. If your phone is vulnerable enough to be rooted, it's vulnerable enough to be owned by a malicious app.