They seem to work as standalone apps, you can have both the normal whatsapp and this alternate app active on a single phone. They dont use the whatsapp web interface either, or if they do its not visible on the main application.
This is obviously a massive security risk, surely there is a way for WA to verify the integrity of the APK before accepting requests to their API?
Not really, no. It's an arms race. They just permanently ban accounts and associated FB/IG/etc accounts at random upon detecting this.