One of these mirrors had a altered version of XCode that Chinese developers were downloading. One of these developers noticed strange behavior with one of his apps. It was connecting to strange servers on the Internet when he hadn't written the code to do so. This lead to the discovery of malware in some copies of XCode floating around the Chinese portion of the Internet.
I imagine Apple will add some sort of tool verification step to help fix this issue. Another way to help prevent this problem would be to host an official mirror inside China, obviating the need to get Apple tools from unofficial sources.