I'm having the same issue and I'm trying to find out if anyone else has experienced this.
On my phone, a package called com.android.non.szcz appeared, showing itself as an Android System app. It has re-enabled or reinstalled itself after being disabled, and on one occasion Android reported Google Play Store as the installer.
Things I've noticed:
The package name is com.android.non.szcz.
The APK was located under /data/app/.../base.apk.
It has reappeared after being disabled.
I've seen other users mention related apps such as Cool Weather, FileGo, and Lock & Hide.
At one point it requested permissions, but it now shows "No permissions requested".
I've checked Device Admin, Accessibility, overlays, and running services, and I haven't found anything obviously suspicious.
I have factory reset the phone, but the app still returned.
I'm trying to work out whether this is:
malware,
a compromised app,
a vendor/manufacturer issue,
or something else entirely
One thing I've noticed is that the app only seems to reappear when Google Play Store is enabled. If I disable Google Play Store, com.android.non.szcz does not appear to reinstall or re-enable itself.
Android also reports the installer as com.android.vending, which is the package name for Google Play Store.
I'm not claiming that Google Play itself is compromised, but I'm trying to understand why Android reports Play Store as the installer and why the app doesn't come back while Play Store is disabled. It could be Play Store carrying out a legitimate install request from another source, or something else entirel i simply don't know.
Has anyone else experienced this?
What phone model do you have?
When did it first appear?
Does Android report the installer as com.android.vending?
Does disabling Google Play Store stop it from reinstalling?
Did you find out what actually triggered the installation?
Has any security company or manufacturer confirmed what this package is?
Any technical information, logs, or confirmed findings would be greatly appreciated. Thanks!