
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
facepy
Advanced tools
.. image:: https://raw.githubusercontent.com/jgorset/facepy/master/docs/banner.png
|version| |pythons| |downloads| |build| |license|
.. |version| image:: https://img.shields.io/pypi/v/facepy.svg .. |pythons| image:: https://img.shields.io/pypi/pyversions/facepy.svg .. |downloads| image:: https://img.shields.io/pypi/dm/facepy.svg .. |build| image:: https://img.shields.io/travis/jgorset/facepy.svg .. |license| image:: https://img.shields.io/github/license/jgorset/facepy.svg
.. code:: python
from facepy import GraphAPI
# Initialize the Graph API with a valid access token (optional,
# but will allow you to do all sorts of fun stuff).
graph = GraphAPI(oauth_access_token)
# Get my latest posts
graph.get('me/posts')
# Post a photo of a parrot
graph.post(
path = 'me/photos',
source = open('parrot.jpg', 'rb')
)
Facepy can do more than reading your latest posts and posting photographs of parrots, but you'll have to
read the documentation <http://facepy.rtfd.org>_ to find out how.
Please note that Facepy does not do authentication with Facebook; it only consumes its API. To get an
access token to consume the API on behalf of a user, use a suitable OAuth library for your platform (if you're
using Django, for example, you might use Fandjango <https://github.com/jgorset/fandjango>_).
.. code:: bash
$ pip install facepy
the repository <http://github.com/jgorset/facepy>_.Johannes Gorset made this. You should tweet me <http://twitter.com/jgorset>_ if you can't get it
to work. In fact, you should tweet me anyway.
I work at Schibsted Products & Technology <https://github.com/schibsted>_ with a bunch of awesome folks
who are every bit as passionate about building things as I am. If you're using
Facepy, we probably want to hire you.
FAQs
Facepy makes it really easy to use Facebook's Graph API
We found that facepy demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.