I have auto-update turned on, yet I just discovered CamScanner was apparently stuck on an unsafe version from July. Now CamScanner seems to be removed from the play store, yet I had to remove the app manually. Play Protect still thought everything was fine. I have a Google Pixel running stock firmware. I guess it's time for a factory reset.
I had paid version installed with auto update and I didn't receive any warning via PlayProtect.
Kaspersky blog mentioned that the malware was part of the advertising module; so I assumed it gets activated only on the free version, so I manually scanned using PlayProtect in a mobile with free CamScanner installed.
Since both of the instances I've mentioned has auto update, it's likely they were >July 30. But Kaspersky did mention that the latest version was indeed affected.