Android banking malware is on Google Play over month with over 10,000 installs
lukasstefanko.com
lukasstefanko.com
The safest bet is to avoid installing any software, especially random little games and utilities. You probably don't need them, and they're definitely not worth the risk.
Heart rate (from optical sensor), free topo maps for outdoor, various transport apps (checking when buses/trams will go realistically based on their GPS), car navigation, watching BBC news, translate, use a freakin' calculator, browse phone file system, control my A/V receiver over wifi. And so on and on.
For every app removed I would lose an useful functionality that helps me quite often, for some there ain't any good replacement.
I think smarter is to not any sensitive data in the phone, consider it hacked out of factory and act accordingly.
This article's particular malware requires the user to enable accessibility services for the app, which shows a scary warning and requires the user to manually go into settings (can't be done in a single click). XCodeGhost affected every single user who ran the apps.
Worse, Apple left the malware on users devices and didn't remove hundreds more affected apps from the store until third parties reported them, showing that they were incapable of even simple static analysis of the app binaries. Meanwhile, Amazon and Google had been doing automated static and dynamic analysis of apps uploaded to their stores for years.
The safest way to get an app is from the official website of that app. If they link you to an app store to download it, presumably they're providing the proper actual package name ID that's unique and published by them.