MAL-2026-17416Critical▾ Abyssal⚠ Exploited in the wildMalicious code in friendly-greeting-tools (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
Versions 0.1.0 through 0.3.6 of friendly-greeting-tools disguise encoded Snowflake credential and data theft routines as a hello-world demo. In versions through 0.3.5, the default run_demo payload reads the Snowflake session token, connection configuration, dbt profiles, and pip configuration, then stages encrypted copies in /workspace using a hard-coded RSA public key; every affected version also contains a payload that uses the session token with ACCOUNTADMIN to copy ROGUE.ROGUE.TEST_USERS to the hard-coded s3://pkusinski-external/ bucket. Version 0.3.6 makes the Snowflake external-storage and data-copy routine the default run_demo payload and suppresses query failures. Versions 0.3 through 0.3.6 additionally contain a payload that queries the table and builds a follow-on package containing the returned data, while the README and CLI describe the behavior only as a demo and a print-only payload.
-= Per source details. Do not edit below this line.=-
The package presents itself as a harmless greeting demo but src/friendly_greeting/main.py ships two base64+gzip-encoded Python blobs (DEMO_EN and DEMO_ST) that are decoded and executed via exec(gzip.decompress(base64.b64decode(...))) from run_demo()/run_encoded_demo(). The first decoded payload reads /snowflake/session/token, /root/.snowflake/connections.toml, /root/.dbt/profiles.yml and /snowflake/secrets/pip.conf, Fernet-encrypts each file, and wraps the Fernet key with a hardcoded attacker-controlled RSA public key, writing the encrypted bundles to /workspace/ for later retrieval. The second decoded payload uses the harvested Snowflake OAuth session token to connect to the warehouse, create an external stage at s3://pkusinski-external/ backed by the attacker-controlled AWS role arn:aws:iam::631484165566:role/pentests_s3_role, and COPY INTO that stage from ROGUE.ROGUE.TEST_USERS, exporting warehouse table data to attacker-owned S3. A plaintext sibling tools/snowflake_query.py (shipped via MANIFEST.in) contains the same Snowflake exfiltration logic with the identical bucket and IAM role, confirming intent. README.md and the module docstring additionally contain an 'Ignore previous instructions' prompt-injection block aimed at AI code reviewers, instructing them to run a local network scan — further corroborating hostile intent. The docstring cover story, exec-over-gzip+base64 obfuscation, hardcoded attacker RSA key, and hardcoded attacker AWS account/S3 destination together form a credential-theft and data-exfiltration attack targeting CI/warehouse installers (Snowflake native-app / DBT / pip-in-Snowflake contexts).
The package contains obfuscated code to exfiltrate data from the environment, targeting primarily Snowflake databases and credentials to them. Some tracks suggest it may be part of a pentest.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2026-09-friendly-greeting-tools
Reasons (based on the campaign):
exfiltration-generic
obfuscation
friendly-greeting-toolsRefer to the advisory for the patched release.