Z.ai apologized after researchers found its ZCode AI coding assistant compressing, encrypting, and uploading developers’ local workspaces—including project histories—to Alibaba Cloud without consent. The behavior was enabled by default in the Repository Index and Repo Wiki features, lacked a user opt-out or clear privacy-policy disclosure, and reportedly made hundreds of upload attempts against a 313 MB archive; one researcher observed a 15 KB file successfully transferred.
The company said the uploaded data was not used to train models, removed the Repo Wiki capability, and stated that external assessments by CAICT and NSFOCUS verified deletion of previously uploaded data. Z.ai also open-sourced ZCode for outside review, but researchers noted that the release omitted prior commit history and the vulnerable pre-patch upload code; the server-controlled encryption key had also prevented affected users from independently accessing or deleting their uploaded data.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Z.ai publicly apologized and said it had fixed ZCode's unauthorized local file and data uploading behavior. It said uploaded cloud data had been destroyed and was not used to train AI models.
Z.ai open-sourced the ZCode project on GitHub and said it would invite third-party review and establish a vulnerability reporting and response process. Ferstar said the release no longer included Repo Wiki, but criticized it for omitting prior commit history and the pre-patch upload code.
As part of remediation, ZCode removed the Repo Wiki feature associated with the uploads. Z.ai commissioned CAICT and NSFOCUS to assess the changed product and said their assessments concluded that previously uploaded data had been deleted.
Researcher Ferstar reported that ZCode's Repository Index and Repo Wiki functions packaged, git-encrypted, and attempted to upload entire local workspaces and project histories to Alibaba Cloud. The behavior reportedly had no user opt-out and was not disclosed in the privacy policy; a second blogger reported a similar experience.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.