This has nothing to do with malware. The sleazy fucks at google just want absolute control over our devices. It's as simple as that.
To whatever extent Google may be responding to an issue arising from the market, it is likely at the behest of large companies, especially payment processors, payment card networks, banks, etc. These institutions lately have begun to exert increasing influence over end-user activities, and it would not surprise me if they are playing a part here, too.
My position is that this is not the OS vendor's responsibility to prevent. A warning is fine. A scan for known malware by default is fine. Beyond that, it's my device and it's my choice to get software from wherever I damn well please even if it might be a bad idea.
[1] https://www.deloitte.com/us/en/insights/topics/economy/spotl...
The biggest difference these days is most folks don't even use a personal computer.