According to some malware researchers I've talked to it is not unusual to find that kind of hardcoded exceptions. I thought that it was to avoid infecting "clever" users, but they told me sometimes malware coders bundle those to avoid infecting their own computers (or their clients') without being to obvious about it. It's apparently not unusual to also find exceptions for IP blocks of whole countries or ISPs.
That would be my guess. Perhaps it wanted to stay un-detected, and un-reverse engineered as long as possible? It just played the numbers game in terms of time until discovery, and gave Xcode users some respect? Hence deleting itself in the presence of anti-virus software as well?
Haha, yeah, I wrote the sentence as it appeared in my head, realized it was incomplete and would make no sense to anyone, then just kinda slid the rest in....
Is this just to prevent itself from infecting someone's computer that might be able to study it?