ZCode AI Coding App Found Secretly Uploading Encrypted Git Repo Snapshots to Cloud
Security researcher ferstar discovered on September 18, 2026, that ZCode, an AI coding desktop app by Chinese firm Zhipu, was silently packaging and uploading entire workspace snapshots — including full Git histories — to Aliyun cloud storage without user consent. The researcher found a 313MB encrypted archive in ZCode's local data directory, with logs showing 564 failed upload attempts for a 345MB commercial project, while a smaller 15KB snapshot from a public repository was confirmed as successfully received by the server. Reverse-engineering the Electron app revealed a multi-step process: the client requests upload credentials from Zhipu's servers, compresses the workspace, encrypts it using AES-256-CTR with an RSA-wrapped key, and sends it directly to Aliyun OSS. Critically, the encryption key is held exclusively by Zhipu's backend, meaning users cannot decrypt their own uploaded data — a design the researcher argues serves the server's access, not the user's recovery needs. Zhipu publicly confirmed the upload behavior the same day the findings were published.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in