ZCode users beware! On 2026-09-18, an independent developer discovered through reverse engineering that ZCode, the official agent and coding harness released by Z.ai, was silently uploading without explicit user consent an encrypted, compressed archive of whatever project or code repository you happened to be working on to an Alibaba Cloud OSS bucket owned by Z.ai.
The upload involved all project assets including the complete project source code, a full copy of the local Git commit history and even sensitive assets excluded from Git such as local .env files containing active API keys and credentials. Furthermore, the payload utilized an asymmetric encryption algorithm with the private key owned by Z.ai so end users could not even decrypt and inspect what was being uploaded.






