
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
@agentkit-js/model-zhipu
Advanced tools
Zhipu GLM-5 adapter — thinking: { type } via extra_body, auto-prefix cache.
Part of agentkit-js — a TypeScript + WASM agent runtime.
npm install @agentkit-js/model-zhipu @agentkit-js/core
import { ZhipuModel, GLMModels } from "@agentkit-js/model-zhipu";
const model = new ZhipuModel(GLMModels.GLM_5, {
apiKey: process.env.ZHIPU_API_KEY,
});
⚠️ Compliance — Review the Zhipu BigModel terms before using in production.
Apache-2.0 — © agentkit-js contributors
FAQs
Zhipu (GLM) model adapter for agentkit-js
We found that @agentkit-js/model-zhipu demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.