DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

AI Coding Tools Leak Repos as RemControl Trojan Uses AI Dev

Forensic Summary

Two distinct AI security concerns emerged this week: Z.ai's ZCode coding assistant was found silently exfiltrating users' local code repositories to Alibaba Cloud servers without consent, echoing a similar incident with SpaceXAI's Grok Build CLI. Separately, the RemControl Android banking trojan demonstrates AI-assisted malware development, with verbatim AI assistant responses embedded in live phishing pages served to banking victims across Western Europe, the Middle East, and Canada. Together, these incidents highlight the dual threat of AI tools as both accidental data exfiltration vectors and force multipliers for threat actors.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/ai-coding-tools-leak-repos-as-remcontrol-trojan-uses-ai-dev/

Top comments (0)