It has been widely reported that the XcodeGhost malware has affected dozens of legitimate apps in the Chinese App Store with 76 popular apps being affected so far, reported by iFeng News, including WeChat, apps from China Mobile and Citic Bank, etc.
Before we can see a fix from Apple or app developers, the well-known jailbreak team, Pangu team, has recently cooperated with UCloud and released a tool, with some additional help on the affected app list from 360 (that cooperated the TaiG jailbreak team) to check if your device is affected by the XcodeGhost malware. Here’s how to do it:
Head over to the XcodeGhost malware checking tool page under Pangu’s site here from your mobile browsers, works on both Safari and Chrome. Click the blue button with white words 立即下载 to initiate the installation of the tool. Click install when you see the prompt message.
After downloading and installation, once you launch the app, you will be prompted as this enterprise app is not trusted on your iPhone.
So open the Settings App, go to General, scroll down to Profiles, go into Profiles and you will see the profile named as Shenzhen Avaintel Technology Co., Ltd. to be trusted at your action. Tap it and press the Trust button when you get prompted with the message below.
Now you are good to go. Go back to Homescreen and open the XcodeGhost malware checking tool. Press the button in the middle titled “点击检测Xcode病毒” and it will start checking. You will see a big green tick if you are not affected. Otherwise, it will advise you with what is infected and to be removed from your device temporarily until it was fixed by the developers.
Hope this help you out in checking if XcodeGhost malware infected on your device. Thanks for reading!
Update #1: over 3400 apps were found infected by XcodeGhost as per the Pangu team. And some download sites/gaming engines may be affected too. This may spread out to Android as well.
Update #2: The app now support scanning list of over 4000 infected apps. If you have installed the first version, launch the app and it will prompt you to update.