One of these mirrors had a altered version of XCode that Chinese developers were downloading. One of these developers noticed strange behavior with one of his apps. It was connecting to strange servers on the Internet when he hadn't written the code to do so. This lead to the discovery of malware in some copies of XCode floating around the Chinese portion of the Internet.
I imagine Apple will add some sort of tool verification step to help fix this issue. Another way to help prevent this problem would be to host an official mirror inside China, obviating the need to get Apple tools from unofficial sources.
I don't know what the best answer is, but Gatekeeper could stand to be a little less obstructive when the user legitimately trusts something that the system doesn't know about.
Apple's answer will, sadly, probably be to make it impossible to disable.
The page also says Apple is working on making it faster for them.
Apple has said that they will now cache downloads inside China to mitigate this.