I assume the bank apps have functionality that their websites lack. Like being able to tap to pay for things, etc. Where a rooted phone might make fraud easier. If not, then this really makes no sense.
The only way an app can contact a company is through REST APIs.
Malware is more easily spread onto rooted phone, that's for sure.
From they you can keylog. Highjack input listeners, basically do anything you want.