
Research
/Security News
Intercom’s npm Package Compromised in Ongoing Mini Shai-Hulud Worm Attack
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.
funcs
Advanced tools
funcsFunctional programming in Python.
Python 3.8 or above is required.
pipInstalling the library with pip is quite simple:
$ pip install funcs
Alternatively, the library can be installed from source:
$ pip install git+https://github.com/nekitdev/funcs.git
Or via cloning the repository:
$ git clone https://github.com/nekitdev/funcs.git
$ cd funcs
$ pip install .
uvYou can add funcs as a dependency with the following command:
$ uv add funcs
You can find the documentation here.
If you need support with the library, you can send an email or refer to the official Discord server.
You can find the changelog here.
You can find the Security Policy of funcs here.
If you are interested in contributing to funcs, make sure to take a look at the
Contributing Guide, as well as the Code of Conduct.
funcs is licensed under the MIT License terms. See License for details.
FAQs
Functional programming in Python.
We found that funcs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
Compromised intercom-client@7.0.4 npm package is tied to the ongoing Mini Shai-Hulud worm attack targeting developer and CI/CD secrets.

Research
Socket detected a malicious supply chain attack on PyPI package lightning versions 2.6.2 and 2.6.3, which execute credential-stealing malware on import.

Research
A brand-squatted TanStack npm package used postinstall scripts to steal .env files and exfiltrate developer secrets to an attacker-controlled endpoint.