This is a good example of how "app stores" tend to provide a false sense of security about what you're really downloading. There are clearly failures in terms of vetting what's there and towards ensuring that the user is actually getting what they think they're supposed to be getting.
Perhaps the "app store" model is still generally better than downloading executable code from completely random sources (nobody should be doing that), but I'm not sure there's anything more reliable (and also "secure") here than downloading a piece of software from its official source (such as from a server under the domain of the known publisher), verifying hashes/signatures, and leaving out as many intermediaries as possible who often have motives not fully aligned with the software user. Of course, this would require users to possess and be willing to use some knowledge of basic software and data hygiene, but it seems that along the way we have somewhat given up on that and so now we're stuck trusting these intermediaries usually much more than they ought to be trusted.