Apple withdraws some China apps after malware found

BEIJING (AP) — Apple Inc. has removed some applications from its App Store after developers in China were tricked into using software tools that added malicious code in an unusual security breach.

Apple gave no details of which companies were affected. But Tencent Ltd. said its popular WeChat app was affected and the company released a new version after spotting the malicious code. Chinese news reports said others affected included banks, an airline and a popular music service.

The malicious code spread through a counterfeit version of Apple’s Xcode tools used to create apps for its iPhones and iPads, according to the company. It said the counterfeit tools spread when developers obtained them from “untrusted sources” rather than directly from the company.

The malicious software collects information from infected devices and uploads it to outside servers, according to Palo Alto Networks, a U.S.-based security firm, which investigated the malware. It was first publicized last week by researchers at Alibaba Group, the e-commerce giant, who dubbed it XcodeGhost.

Cybersecurity experts say the episode shows that any device, including those running Apple’s iOS software, can be vulnerable to hackers even though Apple is known for rigorously scrutinizing apps that are offered in its store.

“I wouldn’t say that the floodgates for iOS malware are open now, but this vector is probably something that other attackers are going to try to replicate in the future,” said Ryan Olson, director of threat intelligence for Palo Alto Networks, in an interview. He said Apple is undoubtedly working on improving its ability to block similar attempts.

Hackers are increasingly looking for new ways to target mobile apps and devices, including iPhones, because they are so widely used by many consumers, added Darren Hayes, a cyber-security expert at Pace University in New York.

The creators of this malware took advantage of public frustration with Beijing’s Internet filters, which hamper access to Apple and other foreign websites. That prompts some people to use copies of foreign software or documents that are posted on websites within China to speed up access.

“Sometimes network speeds are very slow when downloading large files from Apple’s servers,” wrote Claud Xiao, a Palo Alto Networks researcher, on its website. Due to the large size of the Xcode file, “some Chinese developers choose to download the package from other sources or get copies from colleagues.”

Companies with apps that were affected include taxi-hailing service Didi Kuaidi, Citic Industrial Bank, China Southern Airlines and the music service of NetEase, a popular Web portal, according to the newspaper Yangcheng Evening News.

The incident is the only the sixth time malicious software is known to have made it through Apple’s screening process for products on its App Store, according to Xiao.

___

AP Technology Writer Brandon Bailey in San Francisco contributed to this report.

More in News

Eaglecrest Ski Area as seen in a photo posted to the hill’s Facebook page on Tuesday, Dec. 11, 2025. (Eaglecrest Ski Area photo)
Eaglecrest boots up for a limitted opening this weekend

15 degree highs usher in the hill’s 50th season.

Sen. Jesse Bjorkman, R-Nikiski, speaks Wednesday, April 23, 2025, on the floor of the Alaska Senate. (Photo by James Brooks/Alaska Beacon)
State senators express skepticism about proposed Juneau ferry terminal backed by Dunleavy

In a Friday hearing, members of the Alaska Senate spoke critically about… Continue reading

SouthEast Alaska Regional Health Consortium is one of the primary health care providers in Juneau, accepting most major public and private insurance plans. (Mari Kanagy / Juneau Empire)
Marketplace health premiums set to rise in 2026

Here’s what you need to know about how coverage is changing, and for whom.

Capital City Fire/Rescue completes last season’s ice break rescue training at the float pond near Juneau International Airport. (photo courtesy of Capital City Fire/Rescue)
On thin ice: Fire department responds to season’s first rescue at Mendenhall Lake

This week’s single digit temperatures have prompted dangerous ice ventures.

Brenda Schwartz-Yeager gestures to her artwork on display at Annie Kaill’s Gallery Gifts and Framing during the 2025 Gallery Walk on Friday, Dec. 5. (Mari Kanagy / Juneau Empire)
Alaska artist splashes nautical charts with sea life

Gallery Walk draws crowds to downtown studios and shops.

A totem pole, one of 13 on downtown’s Totem Pole Trail in Juneau, Alaska, Nov. 27, 2024. (Christopher S. Miller/The New York Times)
Downtown Juneau experiences its first significant city-level snow fall of the season as pictured on Saturday, Dec. 6, 2025. (Mari Kanagy / Juneau Empire)
Sub-zero temperatures to follow record snowfall in Juneau

The National Weather Service warns of dangerous wind chills as low as -15 degrees early this week.

Most Read