This instance of ransomware on the Mac App Store is mind boggling. I thought the apps listed on the Mac App Store are heavily sandboxed and that they couldn’t get more permissions without somehow making the user change settings in System Preferences (and even that wouldn’t be the same as installing a binary downloaded from the web). How does an app get through reviews and technical restrictions?
When it comes to the app stores, Apple’s negligence over the years while making more than 70% margins on services (which is where app store revenue is counted, AFAIK) is appalling. I’ve avoided spending money on these app stores, and prefer buying from reputed developers for macOS apps. Unfortunately, that’s not possible for iOS.