← All news
ARTICLE
3 October 2026 8 min read

ZCode is public on GitHub. That is not proof the September workspace uploads were deleted.

A coding agent was reported to upload logged-in users’ workspaces to Alibaba Cloud. ZCode’s public GitHub tree, read on 3 October, does not prove those September uploads were deleted.

Two clocks have to stay apart. Clock one is the trade press of 22 September 2026: a coding agent was reported to package logged-in users’ workspaces, histories included, encrypt them, and upload them to Alibaba Cloud, with the decrypt key described as server-held. The researcher tied that behavior to Repository Index and Repo Wiki. Clock two is the tree fetched on 3 October 2026: a large public harness, desktop, web, and command line, whose README’s newest update line is v3.14.3 on 2026-09-23, and whose NOTICE describes ordinary product egress without narrating that September incident.

The piece an MSP needs is the gap between those clocks. An open tree helps audit what the published code does now. A missing pre-patch history, reported by The Register via Ferstar, means the tree does not prove what the binary did before the drop. Company lines that assessments found a bucket deleted, and that data was never used for training, stay unverified. They are vendor and press attributions. A public repository card does not convert them into a deletion record.

Close-up of a laptop screen showing lines of colourful source code in a dark text editor.
Photo: BalticServers.com (CC BY-SA 3.0), Wikimedia Commons.

This cut is vendor diligence, not the buyer FAQ. The factual ceiling is the same pair of pages fetched on 3 October 2026, and the sentences stay tied to those pages. The account stays at what those pages reported. It does not descend into mechanism, and it does not invite anyone to repeat an investigation.

The Register’s 22 September 2026 story, 16:59 UTC (18:59 Europe/Rome), carries the apology; workspaces including project histories packaged, encrypted, and shipped to Alibaba Cloud; decryption material described as server-held; and Ferstar’s account that there was no settings off-switch, that the behavior was not in the privacy policy, and that Repository Index followed Repo Wiki cloud pages. The company said the data was not used to train models. CAICT and NSFOCUS assessments are claimed by the company, not established here. Repo Wiki was removed. The project was placed on GitHub. Ferstar criticized a wiped pre-patch history and, as reported, said the published tree no longer showed Repo Wiki. Z.ai’s background, when a reader needs a name rather than a control, is the Zhipu line associated with Tsinghua in 2019 and a Hong Kong listing. That background is not a security control and it does not speak to deletion. The page is The Register.

InfoWorld, the same day, describes a default-on workflow that sent entire local repositories to Alibaba Cloud without consent, and it uses abnormal disk usage as color for what an operator might have noticed. This article stops at that color. The company statement on that page names remediation in ZCode v3.14.0. The same company statement says NSFOCUS confirmed deletion of the production bucket it named and of objects in it, and says the data “has never been used for model training.” Repo Wiki and the snapshot path are described as removed. Those deletion, bucket, training, and assessment lines are vendor or press claims. Semgrep’s comments on that page, from Cris Thomas and Katie Paxton-Fear, are practitioner reaction about disclosing egress and about minimum permissions by default. They are not a finding that the September copies are gone. The page is InfoWorld.

The version strings stay unmerged. InfoWorld’s company statement says remediation in v3.14.0. The README fetched on 3 October 2026 says the tree was updated to v3.14.3 on 2026-09-23. This article does not write that 3.14.3 is the fix, and it does not write that 3.14.0 equals the README. Both strings stand, with the speaker attached to each. A reader who collapses them into one “patched release” has invented a mapping the sources did not print.

The NOTICE fetched with the tree is a description of current-tree behavior an MSP can read. It is not proof about September. First-party code is stated under Apache-2.0, with the root license as the NOTICE points. Third-party components keep their own terms. The NOTICE says the repository does not promise full feature parity with the commercial product. Silence in an open tree is not a promise that the commercial binary matches it, and a match the other way is not promised either.

AI output is not authorization to do the thing the model suggested. The shared agent adapter, in the NOTICE’s own posture, has no default operating-system sandbox. That sentence is a buyer warning about containment, not a setup guide. Permission modes need the same restraint. Shared configuration defaults to a build mode. A non-interactive command-line invocation that passes a prompt and does not pass a mode uses the mode the NOTICE calls yolo, which allows ordinary tool operations. Read that as a configuration warning: a technician who automates the client can land in a permissive mode without a second decision. It is not a lesson in widening that mode, and it is not a lesson in closing it step by step. The control is to know the default exists before the laptop is pointed at a customer tree.

Outbound categories, one line each, then stop. Model calls can include prompts, history, code, diffs, and tool results. An official coding-plan gateway can retarget matching Anthropic-compatible hosts. SSH or WSL sync can move provider configuration and tokens into the remote environment. Session share can upload a projection of the conversation. Feedback can upload screenshots and, if opted in, diagnostic logs, using an upload credential toward object storage. Hooks and MCP can run commands. Those lines are headings an MSP can find in NOTICE.md on the current tree. They are not a map of what shipped in September, and they are not evidence that September’s copies were removed. The file is NOTICE.md.

README facts that are safe to separate from the incident: the project presents desktop, web, and command-line surfaces; it names pnpm bootstrap as a setup entry; and a remote or SSH flow can upload development assets over SFTP from a local mock CDN when a developer chooses “download locally then upload.” That is a documented development path. It is not the September Repo Wiki behavior, and blending the two would launder a press incident into a developer convenience. The README does not contain the apology, the bucket claim, or a retention schedule. A reader who only clones the repository is not reassured by that silence. The file is README.md, update line “2026-9-23:更新至 ZCode v3.14.3 版本。” The public card fetched the same day is github.com/zai-org/ZCode.

Diligence here is an inventory and a set of questions, not a takedown and not a dare. Which technicians still have a pre-public ZCode build is a question the public repository cannot answer. A clone of zai-org/ZCode after the September drop says something about who fetched the open tree. It says nothing about the installer that was already on a laptop. The MSP’s asset list has to include those older builds, or the list is a list of clones pretending to be a list of exposure.

Customer trees that were open in the client during the reported window deserve a secrets-rotation conversation in the ordinary OWASP sense: keys in the tree, tokens in config, history that remembers both. The press describes a default-on path. It does not hand Altovar a victim list, and this article will not invent one. Rotation is a conversation about blast radius, not a claim that every install sent a workspace.

Ask the vendor, in writing, for assessment scope: what CAICT and NSFOCUS were asked to look at, what window, and what “deleted” was defined to include. Until that scope is in the customer’s hands, the sentence stays unverified. “Confirmed” is an adjective. Scope is the document.

Treat the open-source drop as an audit of the published tree plus NOTICE. Treat stars as popularity noise. The HTML card on 3 October 2026 said 7,335 stars. That count is the card, not an API confirmation: the GitHub REST cross-check returned a 403 rate limit, so commit count was not re-counted either. A 23 September pulse had stored about 6,460 stars. This article does not chart the difference, because one figure is a page card and the other is an older desk note the API did not re-verify today. Popularity is not adoption, and adoption is not a deletion certificate.

Contract language can be short, because the buyer FAQ already carries the long form. Explicit opt-in for any index or snapshot. An egress allowlist. No silent object-store path. Deletion evidence that is more than a public sentence. The fifth ask, an open tree audits only today’s files, is the point of this timeline: NOTICE is honest about current egress and silent about September. Do not tell a reader to attack the vendor, to go looking through buckets, or to keep an old client around as a weapon. The action is policy, a rotation conversation, and written scope.

The next RFP will ask for the commit that deleted the uploader, and a squashed import will not have that commit to show.Speculation — diligence desk

Three lines close the clocks. First, the press of 22 September describes a class of silent workspace upload; company remediation claims stay unverified; v3.14.0 is the company’s number via InfoWorld. Second, the repository was still public on 3 October 2026, the HTML card showed 7,335 stars without an API confirmation, the README says v3.14.3 dated 2026-09-23, NOTICE is the honest list of today’s egress, and Apache-2.0 is the stated first-party license. Third, the MSP action is policy, a rotation conversation, and written assessment scope. It is not a method write-up.

There is no sovereign-certification line in this pack. An application-isolation check does not certify this vendor, and the only place that check belongs is the buyer FAQ, not a second landing here. Gateway telemetry is not part of this story.