
Z.ai ZCode Default Setting Exfiltrated Git Repositories to Alibaba Cloud
AI coding defaults and trojan development artifacts reveal systematic leakage of code and credentials. Patterns link Z.ai, RemControl, and super-app data aggregation through unvetted automation paths. Enterprises face expanding third-party exposure without contractual controls.
ZCode's workflow generated and transmitted full repository snapshots without explicit consent, exposing source code to Chinese infrastructure. Group-IB analysis of RemControl shows AI-generated phishing overlays with verbatim assistant output and Russian comments, routed via Telegram dead-drops. These cases share a pattern: default telemetry or automation paths bypass review, turning developer and banking tools into data pipelines.
Evidence trails confirm the incidents. Z.ai opened its client codebase after public exposure; prior SpaceXAI Grok Build uploads were documented in storage bucket logs. CISA and FBI fact sheets on ICS integrators highlight least-privilege failures that enable similar third-party access abuse, though they omit AI coding assistants. University forensic work on VK's MAX super-app reveals state-mandated data flows across messaging, banking, and government modules.
Operational significance lies in supply-chain normalization. Enterprises integrating AI coding tools inherit unvetted exfiltration without contract visibility. Next indicators include telemetry spikes from other assistants and procurement records showing increased use of Chinese or Russian AI components in Western stacks.
Z.ai: Three additional AI coding platforms will disclose default repository uploads within 120 days.
Sources (3)
- [1]Group-IB RemControl Analysis(https://www.group-ib.com/blog/remcontrol-trojan)
- [2]CISA ICS Integrator Fact Sheet(https://www.cisa.gov/publication/ics-third-party-access-2026)
- [3]University MAX Super-App Forensics(https://www.usenix.org/conference/2026/presentation/max-surveillance)