In brief
If you installed an affected app, check for and install its update. In its response to the 2015 Xcodeghost incident, Apple said it was removing infected apps and blocking new ones, with no indication at the time of malicious incidents or transmission of personally identifiable information.
Several days have passed since the App Store incident involving Xcodeghost-infected apps, and Apple has finally issued an official notice today addressing the incident and advising users on how to respond.
What happened?
Apple first explained that the incident arose because developers downloaded a pirated version of the Xcode development tool that had been infected with malware. The apps built with it were also infected. Developers downloaded the pirated version of Xcode from sources other than Apple's official channels to speed up their downloads.
How does this affect users?
Apple stated that there was currently no indication that the infected apps had caused any “malicious incidents”, nor was there any indication that these apps had been used to transmit any personally identifiable information. The malware also could not obtain passwords for iCloud or other services through users' identities.
What should users do?
Apple said that, whenever it identifies infected apps, it immediately removes them from the App Store. It has also blocked new infected apps from entering the App Store. If you have already installed any of the infected apps, check whether updates are available. If an update is available for the app, installing it will resolve the issue. Previously affected apps that have returned to the App Store have been updated to remove the malware; updates will soon be completed for any app that has not yet returned.