This has nothing to do with malware. The sleazy fucks at google just want absolute control over our devices. It's as simple as that.
To whatever extent Google may be responding to an issue arising from the market, it is likely at the behest of large companies, especially payment processors, payment card networks, banks, etc. These institutions lately have begun to exert increasing influence over end-user activities, and it would not surprise me if they are playing a part here, too.
My position is that this is not the OS vendor's responsibility to prevent. A warning is fine. A scan for known malware by default is fine. Beyond that, it's my device and it's my choice to get software from wherever I damn well please even if it might be a bad idea.
[1] https://www.deloitte.com/us/en/insights/topics/economy/spotl...
And besides if you really want to combat fraud stop using creditcards for fuck sake and make a modern payment system that doesn't rely on 1970s technology.
The biggest difference these days is most folks don't even use a personal computer.
This trust me bro, our App Store is safer is just getting on my nerves. Every day we get malware popping on both app stores.
Time to switch