Nowhere does that require you to go and get a DUNS number, which is onerous for a single developer to do without the infrastructure of a company.
They can already target malicious apps via Play Protect, including presumably all apps signed by the same signing key, so from that point of view no change would be needed. What this is presumably supposed to achieve is rather making it harder to rotate your signing key after it has been burnt…