⚠️ Warning: Fake / Malicious GLM Repository on GitHub (Phishing & Virus)

#23
by WDDW - opened

Dear GLM team,

I would like to report a fake and potentially dangerous repository impersonating the official GLM project on GitHub.

Malicious repository link:
https://github.com/GLM-5-1/GLM-5.1

Issue:
This repository pretends to be an official GLM-related project, but its Releases section contains suspected malware / phishing software (e.g., password-protected archives or executable files). Users who download and run these files may be at risk of credential theft or system infection.

Suggestion to the community:

Please do NOT download any release files from the suspicious repository.

@THUDM team, could you please:

Consider issuing a public warning to your community (e.g., pin a notice or tweet).

Report the malicious repository to GitHub Security if you have not done so already.

Thank you for your attention and for maintaining the safety of the open-source ecosystem.

Best regards

We will check this issue in the next two days. Thank you for bringing this to our attention.

Hello everyone,

I previously reported a fake GLM repository, and it has now been taken down (404). However, a new malicious repository has appeared:

🔗 https://github.com/Zai-glm/GLM-5.1

This fake repo ranks quite high in Bing search results for "GLM-5.1". The attacker didn't even bother to change the README.md — it's very likely the same person, and they are still targeting you.

What I have done so far:

Reported the malware to Huorong (火绒). They have already added detection for the malicious package.

Tested with other antivirus software:

Microsoft Defender (with reputation-based protection enabled) can directly delete it.

360 Security can also detect and remove it.

Advice for users:

As long as your security software's virus definitions are up to date and at least one real-time protection is enabled, this malware should have a hard time executing — unless the attacker releases a new variant.

I'm afraid I've done everything I can at this point. I'm out of options.

Finally, I would like to express my sincere thanks to the GLM team, ZHANGYUXUAN-zR, and Z.ai org for your hard work. Thank you for continuously maintaining high-quality open-source models and for taking security issues like this seriously. I hope my feedback is helpful to you. Please be aware of this new impersonation attempt.

Thank you all.

Sign up or log in to comment