If this can happen, is it possible that once mandatory developer verification comes into effect, all 3rd party apps will be uninstalled at first and require a re-install?
Concerning this specific case, NFCGate is a tool on which malware (family) titled NGate by ESET is based, thus likely causing a false positive.
Oh, and no bypass is available anymore (aside from disabling play protect):



Samsung phones include McAfee, oddly.
At the rate that software was bloating over the years, I’m surprised humanity has produced enough RAM already to load the latest version.
Ill bet that it shares no code with PC mcafee, and its just a rebadge over something else.