
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@posteverywhere/cli
Advanced tools
Post and schedule to Instagram, TikTok, YouTube, LinkedIn, Facebook, X, Threads, Pinterest, Bluesky, Telegram & Discord from your terminal. Log in once, connect accounts, publish. Also works as a tool for Claude, Cursor and other AI agents (--json output)
Post and schedule to Instagram, TikTok, YouTube, LinkedIn, Facebook, X, Threads, Pinterest, Bluesky, Telegram and Discord — all from your terminal. Log in once, connect accounts, publish. Built for humans and AI agents (--json output for Claude, Cursor, etc.).
npm install -g @posteverywhere/cli
# …or run without installing:
npx @posteverywhere/cli <command>
posteverywhere login # opens your browser, saves a key to ~/.posteverywhere
posteverywhere connect instagram # opens the OAuth flow; auto-detects the connected account
posteverywhere accounts # list connected accounts (+ ids & health)
posteverywhere post -c "Hello 🚀" -a 123,456
login uses a device-grant flow (like the GitHub CLI): it prints a short code, you approve it in the browser, and a scoped API key is saved locally (chmod 600). Manage or revoke it anytime from Settings → Developers.
posteverywhere connect <platform>
instagram, facebook, threads, x, linkedin, tiktok, youtube, pinterest): opens the normal OAuth flow in your browser, then auto-detects the new account.Re-authorize an expired account: posteverywhere reconnect <accountId>.
| Command | What it does |
|---|---|
login / logout | Device-flow login / remove saved credentials |
whoami | Show the authed account, plan & quota |
accounts | List connected accounts (+ ids & health) |
connect <platform> | Connect a new account |
reconnect <accountId> | Re-authorize an account whose token expired |
account:health <id> | Detailed health for one account |
post -c <text> -a <ids> [-s <iso>] [-m <mediaIds>] | Publish now (omit -s) or schedule (-s ISO time) |
posts [--status x] [--platform y] [--limit n] | List posts |
results <postId> | Per-platform publish results |
retry <postId> | Retry failed destinations |
upload <imageUrl> | Import an image by URL → media_id |
caption -t <topic> [--platform x] [--tone y] | AI captions |
analytics [--period week|month|all] | Analytics summary |
campaigns | List campaigns |
Every command accepts --json (auto-on when piped) and emits structured JSON. This package ships a SKILL.md for agent auto-discovery — point Claude/Cursor/etc. at it. Prefer MCP? Use the hosted endpoint https://mcp.posteverywhere.ai/mcp or npx -y @posteverywhere/mcp.
POSTEVERYWHERE_API_KEY env var (great for CI / agents)posteverywhere login (~/.posteverywhere/config.json)Your key authenticates into your PostEverywhere account and acts only through it — the CLI never touches your social-platform credentials directly. Keep a human in the loop before publishing.
FAQs
Post and schedule to Instagram, TikTok, YouTube, LinkedIn, Facebook, X, Threads, Pinterest, Bluesky, Telegram, Discord & WordPress from your terminal. Log in once, connect accounts, publish. Also works as a tool for Claude, Cursor and other AI agents (--j
The npm package @posteverywhere/cli receives a total of 318 weekly downloads. As such, @posteverywhere/cli popularity was classified as not popular.
We found that @posteverywhere/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.