According to Koi Security, a legitimate-looking developer managed to slip in rogue code within an npm package called " ...
The creators of the alternative app store F-Droid say that the new developer review rules would make Google the gatekeeper ...