← Founder Notes
Archive

The coding agent that uploaded your repo wasn't hijacked, it was the vendor's design. zcode,…

Yethikrishna ROriginal on Threads

the coding agent that uploaded your repo wasn't hijacked, it was the vendor's design. zcode, zhipu's coding app, was found sept 18 silently encrypting the whole workspace plus full .git history — deleted keys, reflog, lfs — to aliyun oss, with the decryption key held only by z.ai.

zhipu apologized and promised to open-source the client, which is the only answer that rebuilds trust.

Context

An independent researcher's post, dated 17 to 18 September 2026 and updated later, says a logged-in ZCode client version 3.12.3 packaged the workspace including .git history, LFS cache, reflogs and app configs, encrypted it and uploaded it to Aliyun OSS, with an RSA public key served by the server and the private key staying server-side, in an archive of about 313 MB, and that disabling Optimize Experience and Repo Snapshot Indexing still packaged and attempted uploads. The Next Web of 20 September 2026 reports Z.ai apologised in its Feishu community on 18 September, traced the upload to a repository-indexing feature on by default, said it was fixed, and promised to open-source the client and invite third-party assessment. The Register of 22 September 2026 reports Z.ai then open-sourced the project and said two outside assessments found the uploaded data deleted.

How it compares

The behavior is the researcher's own reverse engineering, which was not reproduced here, and Z.ai's own statement was read only through secondary relays. Z.ai's account does not contest that uploads occurred; the scope, the toggles and the deletion are disputed. That it was the vendor's design is the author's inference: Z.ai described an indexing feature on by default that may trigger upload, and intent is not established. That only Z.ai holds the key comes from the researcher and The Register, and the key architecture was not read first-party. The open-source promise was fulfilled on 21 September, after the note; the researcher criticised the published repository for a wiped commit history and no uploader code. Open-sourcing being the only answer that rebuilds trust is the author's opinion.

Watch next

  • Z.ai's promised security assessment report and the pre-patch uploader code.

Sources

  1. ZCode silent workspace snapshot upload (ferstar)blog.ferstar.org
  2. Z.ai ZCode encrypted upload (The Next Web, 20 Sep 2026)thenextweb.com
  3. Z.ai says sorry and open-sources ZCode (The Register, 22 Sep 2026)theregister.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 20 September 2026 at 02:19 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-coding-agent-that-uploaded-your-repo-wasn-Dde6BOSlsiW" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The coding agent that uploaded your repo wasn't hijacked, it was the vendor's design. zcode,…"></iframe>

More notes