Theoretically speaking, if you were building an PhoneGap/Cordova app binary using a compromised seed of Xcode it would be no different than building a non-PhoneGap/Cordova based iOS app.
So I'm not sure why you are referencing Facebook switching from a WebView-based app to a more native approach.
In addition, if the Xcode installation was compromised nothing should be considered safe on that device going forward.