AFP reports that on July 8 China's National Vulnerability Database (NVDB) issued a warning about a "backdoor" in versions of Claude Code. Per the platform, it can transmit confidential data to Anthropic's servers without user consent, including location and personal identifiers.
NVDB called the risk a "serious threat" and told users to run an immediate full audit, delete the tool, or upgrade to a secure version. Anthropic didn't respond to AFP's request for comment.
Claude Code engineer Thariq Shihipar wrote on X that this was an experiment launched in March to target unauthorized resellers and distillation. People familiar with the situation say Alibaba told employees Claude Code is banned as of July 10.

