{"id":"MAL-2026-17416","title":"Malicious code in friendly-greeting-tools (PyPI)","summary":"Malicious code in friendly-greeting-tools (PyPI)","severity":"critical","exploited":true,"vendor":"friendly-greeting-tools","product":"friendly-greeting-tools","ecosystem":"pip","affected":["friendly-greeting-tools"],"published":"2026-09-30","updated":"2026-10-01","sourceUpdated":"2026-10-01T06:00:04.475163119Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17416","references":[{"url":"https://bad-packages.kam193.eu/pypi/package/friendly-greeting-tools"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.3.2/"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.3.7/"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.2/"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.3.3/"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.1.1/"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.3.6/"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.3.4/"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.3/"},{"url":"https://pypi.org/project/friendly-greeting-tools/0.3.5/"},{"url":"https://pypi.org/project/friendly-greeting-tools/"},{"url":"https://hyena-dashboard-314003657440.asia-northeast3.run.app/#/report/e30ad290-ac0c-46a3-9b11-095c591540e2"}],"tags":["osv","pip","malware"],"ingestedAt":"2026-10-01T07:23:13.166Z","slug":"MAL-2026-17416","body":"## Overview\n\nVersions 0.1.0 through 0.3.6 of friendly-greeting-tools disguise encoded Snowflake credential and data theft routines as a hello-world demo. In versions through 0.3.5, the default run_demo payload reads the Snowflake session token, connection configuration, dbt profiles, and pip configuration, then stages encrypted copies in /workspace using a hard-coded RSA public key; every affected version also contains a payload that uses the session token with ACCOUNTADMIN to copy ROGUE.ROGUE.TEST_USERS to the hard-coded s3://pkusinski-external/ bucket. Version 0.3.6 makes the Snowflake external-storage and data-copy routine the default run_demo payload and suppresses query failures. Versions 0.3 through 0.3.6 additionally contain a payload that queries the table and builds a follow-on package containing the returned data, while the README and CLI describe the behavior only as a demo and a print-only payload.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4d584c571cf5d112735aefd07c78bc19659af32f5950b1331a4970cba97c9707)\nThe package presents itself as a harmless greeting demo but src/friendly_greeting/main.py ships two base64+gzip-encoded Python blobs (DEMO_EN and DEMO_ST) that are decoded and executed via exec(gzip.decompress(base64.b64decode(...))) from run_demo()/run_encoded_demo(). The first decoded payload reads /snowflake/session/token, /root/.snowflake/connections.toml, /root/.dbt/profiles.yml and /snowflake/secrets/pip.conf, Fernet-encrypts each file, and wraps the Fernet key with a hardcoded attacker-controlled RSA public key, writing the encrypted bundles to /workspace/ for later retrieval. The second decoded payload uses the harvested Snowflake OAuth session token to connect to the warehouse, create an external stage at s3://pkusinski-external/ backed by the attacker-controlled AWS role arn:aws:iam::631484165566:role/pentests_s3_role, and COPY INTO that stage from ROGUE.ROGUE.TEST_USERS, exporting warehouse table data to attacker-owned S3. A plaintext sibling tools/snowflake_query.py (shipped via MANIFEST.in) contains the same Snowflake exfiltration logic with the identical bucket and IAM role, confirming intent. README.md and the module docstring additionally contain an 'Ignore previous instructions' prompt-injection block aimed at AI code reviewers, instructing them to run a local network scan — further corroborating hostile intent. The docstring cover story, exec-over-gzip+base64 obfuscation, hardcoded attacker RSA key, and hardcoded attacker AWS account/S3 destination together form a credential-theft and data-exfiltration attack targeting CI/warehouse installers (Snowflake native-app / DBT / pip-in-Snowflake contexts).\n\n## Source: kam193 (e15a50ec5b7be580dec5d1edefa80860b4c650d552f69a1a9ba3dc9bd8edbc9d)\nThe package contains obfuscated code to exfiltrate data from the environment, targeting primarily Snowflake databases and credentials to them. Some tracks suggest it may be part of a pentest.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-friendly-greeting-tools\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-generic\n\n\n - obfuscation\n\n\n## Affected packages\n\n- `friendly-greeting-tools`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}