the supply-check attack in which XcodeSpy malware was used to target developers using Xcode integrated development environment, and a similar malware was used back in 2015. It was codenamed XcodeGhost, and it allowed attackers to insert malicious code in legitimate apps using rogue versions of Xcode downloaded from third-party websites.
Read full article on HackRead