Earlier quoted context omitted.
That's exactly the point, though: side loading is not something to worry about, since normal users won't and shouldn't care about it at all. It is not a threat to the Apple App Store. But it does allow for niche applications such as NewPipe and F-Droid, for technical users who know the risks.
Almost everyone in China uses alternative stores, like Huawei or Xiaomi; how else do you think malicious PDD app got on their phones? The same applies to other counties in South-East Asia. I have seen our app for Android repackaged with malware and uploaded to an alternative store and listed there with hundreds of thousands downloads.
The malicious PDD app is really, actually, published to the alt stores by PDD Holdings itself. It loads the exploit config and post exploitation modules from PDD's own CDN.
It's not the same repackage-with-malware shit plaguing China/SEA market since forever. It's first party.
And the Google Play version contains the same exploit delivery codes, though no real evidence that it was activated.