I guess the argument would be that a screened app store would block such a malicious app.
But since the trick requires the user to go to a malicious website to install this app, it seems to me that the user might similarly be tricked into entering credentials on that website.