Apple (NASDAQ:APPL) last night confirmed it had been the subject of a major malware attack on its app store.
Commentators said it was the most serious attack yet on the iPhone maker, which prides itself on its security and that up to now has managed to restrict hackers to a handful of minor breaches.
Apple said yesterday it had removed a number of apps that had been created in China with a rogue version of Xcode, its software for app developers.
The malware, dubbed XcodeGhost, was a “very harmful and dangerous malware that has bypassed Apple’s code review and made unprecedented attacks on the iOS ecosystem,” according to Palo Alto Networks.
In a post on Sunday, the Internet security firm claimed that the malware had affected 39 apps. Apple did not quantify how many had been involved.
“To protect our customers, we’ve removed the apps from the App Store that we know have been created with this counterfeit software and we are working with the developers to make sure they’re using the proper version of Xcode to rebuild their apps,” it said.
Malware can give access to user’s security details especially passwords, though there was no information if any data had been compromised.
Three Chinese companies, Tencent, which runs the WeChat messaging service, Didi Kuaidi, a journey app, and music streaming firm NetEase, all stated they had been affected but that no consumer information had been lost.
According to the Wall Street Journal, the hackers advertised the infected version of the Apple software on a Chinese server with a promise of faster downloads than the official version.