
Research
PyPI Package Disguised as Instagram Growth Tool Harvests User Credentials
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
A set of tools for connecting and processing data for Annex Brands, featuring API pack and ship quoting.
ABConnect is a Python package that provides a collection of tools for connecting and processing data for Annex Brands. It includes modules for quoting, building, and loading data from various file formats (CSV, JSON, XLSX), with a focus on handling unsupported characters and encoding issues seamlessly.
You can install ABConnect using pip:
pip install ABConnect
For more detailed installation instructions and documentation, visit https://abconnecttools.readthedocs.io/
ABConnect requires the following environment variables for authentication:
# Create a .env file with your credentials
ABCONNECT_USERNAME=your_username
ABCONNECT_PASSWORD=your_password
ABC_CLIENT_ID=your_client_id
ABC_CLIENT_SECRET=your_client_secret
# Optional: Set environment (defaults to production)
ABC_ENVIRONMENT=staging # or 'production'
ABConnect supports both staging and production environments:
from ABConnect.api import ABConnectAPI
# Use staging environment
api = ABConnectAPI(env='staging')
# Use production environment (default)
api = ABConnectAPI()
# Environment can also be set via ABC_ENVIRONMENT variable
For testing, create a .env.staging
file with staging credentials:
cp ABConnect/dotenv.sample .env.staging
# Edit .env.staging with your staging credentials
Tests will automatically use .env.staging
when running with pytest.
Full documentation is available at https://abconnecttools.readthedocs.io/
To contribute to ABConnect, clone the repository and install in development mode:
git clone https://github.com/AnnexBrands/ABConnectTools.git
cd ABConnectTools
pip install -e .[dev]
Run tests with:
pytest
This project is licensed under the MIT License - see the LICENSE file for details.
FAQs
A set of tools for connecting and processing data for Annex Brands, featuring API pack and ship quoting.
We found that ABConnect demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
A deceptive PyPI package posing as an Instagram growth tool collects user credentials and sends them to third-party bot services.
Product
Socket now supports pylock.toml, enabling secure, reproducible Python builds with advanced scanning and full alignment with PEP 751's new standard.
Security News
Research
Socket uncovered two npm packages that register hidden HTTP endpoints to delete all files on command.