If this can happen, is it possible that once mandatory developer verification comes into effect, all 3rd party apps will be uninstalled at first and require a re-install?
Concerning this specific case, NFCGate is a tool on which malware (family) titled NGate by ESET is based, thus likely causing a false positive.
Oh, and no bypass is available anymore (aside from disabling play protect):



Google has control over every aspect of your phone. Some LineageOS versions ago the true permissions were visible. And google play services is crazy mighty. Time to get rid of google entirely in my opinion.