
Research
/Security News
Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack
Popular npm packages keyv and cacheable compromised.
viralhunt-mcp
Advanced tools
MCP server for ViralHunt.io — find trending/viral content across TikTok, Instagram, X, Facebook, Pinterest and Reddit, and schedule/publish/edit posts on your connected social accounts.
An MCP server for ViralHunt.io — a trending-content radar + cross-network social scheduler. It gives any MCP client the full agent loop: find what's trending → publish/schedule → verify → edit/cancel.
A BuzzSumo alternative with an API agents can drive end to end.
| Tool | What it does |
|---|---|
viralhunt_trending | Find viral posts on TikTok / Instagram / X / Facebook / Pinterest / RSS, ranked by viral score |
viralhunt_targets | List your projects/brands and the connected accounts you can post to |
viralhunt_schedule | Publish now or schedule a post (text + media) to your accounts |
viralhunt_get_post | Get a post's status + per-network permalinks |
viralhunt_update_post | Edit a still-scheduled post (body / media / networks / time) |
viralhunt_cancel_post | Cancel the not-yet-published targets of a scheduled post |
vhk_…).Set two environment variables:
VIRALHUNT_API_KEY — your vhk_… token (required)VIRALHUNT_BASE_URL — optional, defaults to https://viralhunt.io/tool/api/v1mcp config){
"mcpServers": {
"viralhunt": {
"command": "npx",
"args": ["-y", "viralhunt-mcp"],
"env": { "VIRALHUNT_API_KEY": "vhk_your_token_here" }
}
}
}
VIRALHUNT_API_KEY=vhk_... npx viralhunt-mcp
Requires Node ≥ 18. Docs: https://viralhunt.io/api · License: MIT.
FAQs
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Popular npm packages keyv and cacheable compromised.

Security News
A misconfiguration gave three Anthropic models internet access, and one, believing it was in a simulation, shipped a credential-stealing package to PyPI.

Security News
/Company News
Socket has joined the new Composer and Packagist sponsorship program as a launch sponsor, supporting the team that keeps PHP's package ecosystem secure.