I understand what sideloading means, as I'm sure the rest of HN knows. But to the layman non-techie, it has indeed been marketed as a boogeyman.
Even in the Android developers blog post:
> We’ve seen how malicious actors hide behind anonymity to harm users by impersonating developers and using their brand image to create convincing fake apps. The scale of this threat is significant: our recent analysis found over 50 times more malware from internet-sideloaded sources than on apps available through Google Play.
The research paper that shows their methodology for discovering these results AHS not been published by Google, to my knowledge. Just a mere "trust me, bro".
Edit to include link to source: https://android-developers.googleblog.com/2025/08/elevating-...