Many US businesses are still running XcodeGhost-infected Apple apps
A new version of XcodeGhost has also appeared that tries to defeat defenses built into iOS 9 — Dozens of U.S. enterprises are still using Apple mobile apps seeded with malware for a clever hacking scheme revealed last month known as XcodeGhost.
Context & Ripple Effects
When researchers surfaced XcodeGhost in late September, the story moved fast: WeChat was among 39 compromised apps, then counts climbed past 4K infected apps before Apple pulled them from the App Store. What this PCWorld report adds is the part that cleanup can't touch — dozens of U.S. enterprises are still running the infected builds on their own devices.
The scale of the original breach stayed hidden until much later: [[a:966092|Apple's own emails disclosed in the Epic trial put it at 128M iPhone users who downloaded XcodeGhost-infected apps, 18M of them in the U.S.]]. A new variant now trying to defeat iOS 9 defenses shows the attack outliving its initial takedown.
First-order effects
- U.S. enterprises running the infected builds carry live malware on managed devices even though Apple has removed the apps from the store — removal fixes distribution, not already-deployed copies.
- The iOS 9-targeting variant raises the stakes for any organization that delayed patching or still runs older app versions.
Second-order effects
- Enterprise security teams must treat App Store vetting as insufficient for internally distributed apps, forcing app-inventory audits and tighter mobile device management policies.
- The attack's origin in a tampered copy of Apple's Xcode toolchain pushes developers toward verifying their build tools directly — a pressure point later exploited by XcodeSpy, which targeted the Macs of Apple OS developers themselves.
Third-order effects
- The pattern points to development-toolchain compromise as a durable attack class: infecting the SDK once reaches every app built with it, so platform owners face growing responsibility for the integrity of tools they distribute outside the store review process.
- If enterprise fleets keep harboring 'removed' malware, expect regulators and large buyers to demand software provenance attestations from vendors rather than trusting app-store curation alone.
The trend: Software supply-chain attacks on developer tools are proving harder to stamp out than the apps they seed, turning SDK governance into an ongoing security battleground rather than a one-time cleanup.