Couldn't malware authors start from the other direction? Create a no-op extension with no permissions and gradually add things until it's no longer approved.
Only years later, as in the case of a certain Vietnamese hacking group that did exactly this starting at the end of 2015 and didn't have their apps yanked until Nov & Dec of 2019 and another batch located & yanked only last month, well after any and all damage was already done to those who used the apps.