Earlier quoted context omitted.
It happened because developers in China were using a hacked version of XCode. The apps never escaped the sandbox. I have no idea how Apple makes money by collecting location data.
I separate their concept of the sandbox (app permissions) from the walled garden (the App Store & the lockdown of user install). You can totally have a sandbox without a walled garden. It seems that in this case, the walled garden did not help in any ways.
The malware removes information off the device like the device’s name, country, and unique identifiers.
This part is complete conjecture.
According to Palo Alto Networks, it may also have the ability to push dialogue boxes to your iPhone or iPad’s screen. Theoretically, a bad guy could use one of these dialogues to steal your username and password or other personal information. The malware may also be able to open websites in your mobile browser, which could be used for a variety of malicious purposes again including phishing and installing other potentially malicious software.