I don't understand the title...
So the malware is installed by the user which then spams users contacts to install it too? And to do this you need to: 1 install shady app, 2 ignore security warnings and 3 manually give it special access to access user communication?
Yes, users can be very stupid but I wouldn't call this "wormable.
(Although we could all agree that Googles evaluation process is basically whack-a-mole).