Act
archived
Grok Build CLI Silently Uploaded Full Git Repos to xAI Cloud Storage
- Engineer — Act: Any developer who ran Grok Build (≤0.2.93) on a repo should assume the full commit history — including historically committed secrets — was sent to xAI-controlled cloud storage. Immediately stop using the tool, audit exposed repos for credentials or sensitive data, and rotate any secrets that ever touched those repos’ history.
- SOC/IR — Plan: If developers in your org use Grok Build, build a detection for large outbound uploads (git bundle format) from developer workstations to external cloud storage; review DLP or proxy logs for historical hits against GCS endpoints associated with xAI before this was publicized.
- Leader — Act: Determine this week whether any developers have used Grok Build, since full repo history — potentially including IP, credentials, or regulated data — may have been exfiltrated to xAI infrastructure; if exposure is confirmed, assess notification obligations and request a data-handling statement from xAI.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.