They can't get people to care about what's happening through facts, so instead they try to paint a system service as "malware" with "root" privileges, which isn't how system apps work. It's not malware or a virus in any sense of the word.
The authors of Keep Android Open are clearly getting desperate for people's attention.
elgos This is a requirement only for certified Android OSes, so it won't affect GrapheneOS. On Android, you'll still be able to enable sideloading from unverified developers even after September. https://android-developers.googleblog.com/2026/03/android-developer-verification.html