An EV cert requirement would make it far more difficult for the malware author to remain anonymous, wouldn't it? The hack may have still happened, but the author could be identified for law enforcement.
I mean that the apps didn't pretend to be banking apps. If you don't mind being warned that non-banking apps don't have EV certs, you wouldn't have minded being warned about these apps and have just installed them.