So Apple users are supposed to be safe because Apple uses just static analysis tools to review the apps before publishing?
The biggest safety precaution against something like this is app sandboxing, which severely limits the amount of damage that a malicious developer can do.
This is a common misunderstanding, and it seems to be one that Apple is happy to spread. Whenever the merits of app review are discussed, some people bring up the security advantages of it. But the fact is, there are none, as XcodeGhost demonstrates nicely. iOS's security is due entirely to the strict sandboxing for third-party apps. App review just lets Apple control what kind of content can be in the store.