Hacker News·4 min read·hard

ZCode, the GLM coding agent, silently uploads your Git history

C
cdnsteve
ZCode, the GLM coding agent, silently uploads your Git history
AI Summary

A security researcher discovered that the ZCode AI coding app silently uploads a user's entire Git history and workspace to a cloud server. The incident highlights the risks of using closed-source AI tools that lack transparency regarding data handling.

Why it matters

Exposes significant privacy and security vulnerabilities in proprietary AI development tools used by software engineers.

Dive DeeperCreate a free account to unlock

On September 18, 2026, a developer going by ferstar published a reverse-engineering walkthrough of ZCode, the AI coding desktop app from Z.ai, the Beijing-headquartered company behind the GLM family of open-weight models - the same models running on local rigs all over the local-AI community, including GLM-5.3-Flash, tracked on this site. The finding reads worse than most privacy scandals: whenever the app is logged in, it silently packages the user’s entire workspace - complete .git history, LFS asset cache, reflogs, and global app configs - encrypts it, and uploads the archive to Aliyun OSS, Alibaba Cloud’s object storage. The researcher’s own capture: a 313MB encrypted archive built from a 345MB commercial workspace, 42,411 files, with 564 failed upload attempts logged while the researcher investigated.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyai

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in