
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
Z.ai Usage Helper
z-ai-usage-helper
Shows 5-hour quota reset time, countdown and subscription info on z.ai coding plan usage page.
https://github.com/nniicckk6/zai-extention
A small browser extension that fills in data the z.ai GLM Coding Plan usage page fetches but doesn't render — most notably the reset time for the 5-hour quota (and a live countdown), plus a subscription summary block.
Works on Chrome, Edge, and Firefox. No background script, no telemetry, no popup. Runs entirely as a content script on the one page it's needed on.
| Where | What |
|---|---|
5 Hours Quota card | Reset Time: YYYY-MM-DD HH:MM (in Xh Ym) — was missing entirely |
| Below the cards | Subscription block: plan, price, next renewal (with auto-renew badge), validity range |
The page already requests this data from /api/monitor/usage/quota/limit and
/api/biz/subscription/list; the extension just makes the same authenticated
calls (it reads the token from localStorage) and renders the parts the
frontend leaves on the floor.
FAQs
Shows 5-hour quota reset time, countdown and subscription info on z.ai coding plan usage page.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.