It's not like the App Store even prevents malware anyway. All Apple does during review is run the app and watch network traffic via a proxy and ask "does this look like it's violating our rules?" There's no instrumentation and there's nothing to prevent apps from changing behavior after the review. These aren't loopholes abused just by flashlight apps but even large companies like Facebook routinely abuse them. Don't forget that you can also get code onto people's phones by providing a completely closed and never reviewed dylib to devs and they'll just include it in their apps if it solves a problem for them. This is another extremely common tactic to distribute iOS malware (and another one Facebook likes.) Also lets not forget all of the outright scams on the AppStore and the fact that it more or less prevents the sharing of community maintained software (chat apps in particular) which tend to align more closely with users interests.
There is absolutely no reason not to allow users to be able to enter an alternate App repository and push service in the settings App other than that it protects Apple's monopoly.