A malicious app campaign that infiltrated Apple's App Store is much more widespread than initially thought, according to security researchers.

Palo Alto Networks' initial report five days ago claimed that 39 malicious apps had passed Apple's rigorous review and evaluation process to eventually end up on China's App Store.
Even that small number was thought to potentially affect hundreds of millions of users, as it included versions of popular software, including the messaging service WeChat.
However, FireEye said yesterday that the number of affected apps is actually closer to 4,000.
The hackers managed to get the malicious apps onto the App Store by producing a malicious version of Apple's Xcode compiler software - XcodeGhost - which they promoted to developers via forums and other similar pages.
The malware is said to steal information about the user and device and transmit that information back to a C&C server. It was initially thought that attackers could then use the information to create phishing asking for iCloud passwords.
However, a new blog post from Appthority suggests that the author of the particular exploit decided not to implement such “harmful behaviors.”
“The identified versions of XCodeGhost actually behaved more like adware or tracking frameworks than malware, and we do not see them as an immediate security threat,” Appthority said.
So, FireEye warned that while the XcodeGhost C&C server is now “down,” the malicious applications are still trying to connect via HTTP.
As such, this HTTP session is “vulnerable to hijacking by other attackers,” it claimed.
