This is the best heuristic to apply not just for QR code scanning, but for pretty much everything. To avoid malware, avoid the Play Store.
When using f-droid, also check out the project web site and git repo (at least in a cursory way, even if you can't fully audit the code, you can get a sense of who the developer is and the project's overall health from the commit log and issue tracker).
Play store should be only used for things that you can't work around with apps from f-droid.
Don't forget it is on the Google Play store too. https://play.google.com/store/apps/details?id=com.google.zxi...
There was a time when QR Code scanning was better in Android than iOS (native in iOS 11.x).
The "Google" way of scanning QR Codes is Google Lens, but it doesn't work offline :|
I believe these bad reviews might be a result of the malware app pushing bad reviews to the zxing app page on google play, using an in app 'rate this app?' -> low rating -> send to the zxing app in Google Play (instead of the malware app in google play).
https://f-droid.org/en/packages/com.secuso.privacyFriendlyCo...