Just to be clear, they didn't obtain any passwords, but auth tokens. This would potentially allow them to log into accounts, but only as long as the tokens are valid.<p>Also, they don't reveal which "third party app stores" served infected apps, but they do provide a list of infected apps, and searching for these yields some real shady download sites: <a href="http://imgur.com/a/0luW3" rel="nofollow">http://imgur.com/a/0luW3</a>