If this can happen, is it possible that once mandatory developer verification comes into effect, all 3rd party apps will be uninstalled at first and require a re-install?
Concerning this specific case, NFCGate is a tool on which malware (family) titled NGate by ESET is based, thus likely causing a false positive.
Oh, and no bypass is available anymore (aside from disabling play protect):

Play protect will remove things that google doesn’t like, not malware.
Working at a phone retail place, I have never seen malware not from the Play store. There is fuckloads of malware on the Play store. Most of it faking Google’s own apps which you’d think they would care about, but they don’t. All of that walks straight through play protect and in some cases on Samsung phones will abuse their security features to not let you remove it easily.
Fake apps that replace your home screen, display ads every 5 seconds, and close any app that you’re in are rampant on the Play store and play protect will do nothing about it.
I uninstalled Google.
You can (and should) also disable Play Protect.
Android scanners are useful for known signatures, but I wouldn’t treat one as a full replacement for good install hygiene. Because of the app sandbox, a normal scanner can’t deeply inspect everything another app does.
Hypatia can help catch known files, but source, permissions, OS/WebView updates, and checking suspicious APKs before installing still matter more. A clean scan also doesn’t mean an app won’t abuse permissions you voluntarily granted it.



