
Research
/Security News
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.
pi-ainetcafe-provider
Advanced tools
ainetcafe provider for pi: Kimi K3 served from ainetcafe's own cluster at native MXFP4 ($2.10 / $10.50 per M tokens), OpenAI-compatible, with thinking-level mapping and live model discovery.
ainetcafe provider for pi. Kimi K3 served from ainetcafe's own cluster at the released MXFP4 precision, $2.10 / $10.50 per million tokens, $0.30 cached input, OpenAI-compatible.
export AINETCAFE_API_KEY=sk-... # Token Management at https://microquickjs.com
pi install npm:pi-ainetcafe-provider
pi
/model # pick ainetcafe/Kimi-K3
Or without installing anything: add the provider to ~/.pi/agent/models.json as described in the pi guide.
ainetcafe with base URL https://microquickjs.com/v1 (override with AINETCAFE_BASE_URL).Kimi-K3 with 256K context, text + image input, reasoning on, and pi's thinking levels mapped to reasoning_effort low / high / max. K3 always thinks, so the off level is marked unsupported./v1/models at startup (5 s timeout) so other models on the account appear too, with conservative defaults.Checked with curl before writing the compat block: reasoning_effort is honoured, reasoning comes back as reasoning_content, function tool calls and streaming with usage work, image input works, thinking: {type: "disabled"} is accepted but does not turn thinking off.
Live availability probe: https://ainetcafe.com/k3/status.html
MIT
FAQs
ainetcafe provider for pi: Kimi K3 served from ainetcafe's own cluster at native MXFP4 ($2.10 / $10.50 per M tokens), OpenAI-compatible, with thinking-level mapping and live model discovery.
The npm package pi-ainetcafe-provider receives a total of 138 weekly downloads. As such, pi-ainetcafe-provider popularity was classified as not popular.
We found that pi-ainetcafe-provider demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Operators behind PolinRider used a compromised GitHub account to plant malware in four development versions of a Packagist package with 700,000+ downloads.

Security News
GitHub Actions now supports cache-mode, a least-privilege control on the Actions cache aimed at the cache poisoning technique behind recent compromises.

Company News
Allow myself to introduce... myself.