All they do either way is poke at the GUI and
maybe watch the HTTP requests.
The real goal of the review process is to maintain control over the UX, not prevent malware. If you want to see a review process that stops malware read a Linux distribution mailing list.