If this can happen, is it possible that once mandatory developer verification comes into effect, all 3rd party apps will be uninstalled at first and require a re-install?
Concerning this specific case, NFCGate is a tool on which malware (family) titled NGate by ESET is based, thus likely causing a false positive.
Oh, and no bypass is available anymore (aside from disabling play protect):



I’d be interested to know what anti-malware tools one can use on an Android other than Play Protect.
There is Hypatia available through F-Droid.
Samsung phones include McAfee, oddly.
At the rate that software was bloating over the years, I’m surprised humanity has produced enough RAM already to load the latest version.
Ill bet that it shares no code with PC mcafee, and its just a rebadge over something else.
Mbam has been on android forever