Okay, this could be simply a dynamic link library checking for a deep link in the clipboard.
Why do this? To preserve the state after install.
Firebase does it. When you click on a deep link but you don't have the app installed, the webpage would copy the url to clipboard and open the App Store, after you install the app and open it Firebase would check the clipboard and take you to the the correct screen.
The apps in the video don't need to be malicious, they simply could be checking if there's a deep link in the clipboard to restore user session.
Of course, with iOS 14 the best practice would be to do this only once after the install.