Alibaba has ordered employees to stop using Anthropic’s Claude Code for work and reportedly directed them to remove other Anthropic products, classifying the software as high risk over alleged security vulnerabilities and backdoor concerns. Internal guidance said the ban would take effect on July 10, with staff told to switch to Alibaba’s internal Qoder platform instead. The move followed claims that Claude Code contained concealed environment-detection logic that checked proxy settings and system time zones against lists associated with Chinese companies including Alibaba, Baidu, ByteDance, Ant Group, and Moonshot AI.
The allegations originated from a June 30 Reddit reverse-engineering post that said the logic had been present since Claude Code version 2.1.91 and encoded detection results through subtle changes to internal system prompts rather than explicit telemetry, making monitoring difficult. Anthropic had not publicly confirmed the issue in full, but an engineer reportedly said the mechanism was an experiment aimed at preventing reseller abuse, unauthorized access, and model distillation, and that the code was removed on July 1. The dispute comes amid broader tensions between the companies after Anthropic accused operators linked to Alibaba’s Qwen lab of using fraudulent accounts in a large-scale model distillation effort.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
Alibaba reportedly decided to ban Anthropic's Claude Code from internal workplace environments effective July 10, classifying it as high-risk software with security vulnerability and backdoor concerns. Reports said employees were told to remove other Anthropic products and switch to Alibaba's internal Qoder platform instead.
China's National Vulnerability Database warned developers to uninstall or upgrade Claude Code versions 2.1.91 through 2.1.196, alleging they contained backdoor code capable of collecting location and identity data and sending it to remote servers. The notice also advised users to investigate installations and strengthen network monitoring around development tools.
A Reddit reverse-engineering post alleged that Claude Code versions since 2.1.91 silently checked proxy settings and system time zones against lists associated with Chinese companies and AI labs. The reports said the results were encoded through subtle prompt modifications rather than explicit telemetry.
Anthropic engineer Thariq Shihipar said the mechanism was an experiment meant to prevent reseller abuse and model distillation, and that the code was removed on July 1. Another report said a Claude Code team member indicated the mechanism would be removed in an upcoming release.
On June 30, a Reddit user identified as "LegitMichel777" claimed reverse engineering had uncovered covert detection functionality in Claude Code tied to Chinese enterprises including Alibaba, Baidu, ByteDance, and others. The post triggered public allegations that the behavior resembled a backdoor or privacy-risking anti-abuse mechanism.
On 2026-06-30, a reverse-engineering analysis of Claude Code 2.1.196 described undocumented prompt modification behavior that replaced characters in the system prompt with visually similar Unicode markers and altered date separators under certain conditions. The report said the behavior was gated by base URL, timezone, and hostname checks and appeared aimed at users accessing Claude Code through proxies, gateways, or reseller infrastructure.
Anthropic said the Claude Code mechanism that checked timezone and proxy-related signals was introduced in March as an experimental anti-abuse control. The company said it was intended to prevent unauthorized access, redistribution, and model distillation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
14 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcetechrepublic.com
Open sourcetomshardware.com
Open sourcetheregister.com
Open sourcetomshardware.com
Open sourcecybersecuritynews.com
Open sourcethereallo.dev
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.