Getting this kind of behaviour past review is simple, and malevolent apps do happen.
Google has a clever technique for detecting them (after review) and it's good, but slow. It has a decent chance of detecting the app after a few attacks, and works by analysing which apps were installed on phones just before a factory reinstall.
This is why the appstores do reviews etc. these kind of things dont happen because of that