---
id: MAL-2026-17416
title: Malicious code in friendly-greeting-tools (PyPI)
summary: Malicious code in friendly-greeting-tools (PyPI)
severity: critical
exploited: true
vendor: friendly-greeting-tools
product: friendly-greeting-tools
ecosystem: pip
affected:
  - friendly-greeting-tools
published: '2026-09-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T06:00:04.475163119Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17416'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/friendly-greeting-tools'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.3.2/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.3.7/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.2/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.3.3/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.1.1/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.3.6/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.3.4/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.3/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/0.3.5/'
  - url: 'https://pypi.org/project/friendly-greeting-tools/'
  - url: >-
      https://hyena-dashboard-314003657440.asia-northeast3.run.app/#/report/e30ad290-ac0c-46a3-9b11-095c591540e2
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-10-01T07:23:13.166Z'
---

## Overview

Versions 0.1.0 through 0.3.6 of friendly-greeting-tools disguise encoded Snowflake credential and data theft routines as a hello-world demo. In versions through 0.3.5, the default run_demo payload reads the Snowflake session token, connection configuration, dbt profiles, and pip configuration, then stages encrypted copies in /workspace using a hard-coded RSA public key; every affected version also contains a payload that uses the session token with ACCOUNTADMIN to copy ROGUE.ROGUE.TEST_USERS to the hard-coded s3://pkusinski-external/ bucket. Version 0.3.6 makes the Snowflake external-storage and data-copy routine the default run_demo payload and suppresses query failures. Versions 0.3 through 0.3.6 additionally contain a payload that queries the table and builds a follow-on package containing the returned data, while the README and CLI describe the behavior only as a demo and a print-only payload.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (4d584c571cf5d112735aefd07c78bc19659af32f5950b1331a4970cba97c9707)
The package presents itself as a harmless greeting demo but src/friendly_greeting/main.py ships two base64+gzip-encoded Python blobs (DEMO_EN and DEMO_ST) that are decoded and executed via exec(gzip.decompress(base64.b64decode(...))) from run_demo()/run_encoded_demo(). The first decoded payload reads /snowflake/session/token, /root/.snowflake/connections.toml, /root/.dbt/profiles.yml and /snowflake/secrets/pip.conf, Fernet-encrypts each file, and wraps the Fernet key with a hardcoded attacker-controlled RSA public key, writing the encrypted bundles to /workspace/ for later retrieval. The second decoded payload uses the harvested Snowflake OAuth session token to connect to the warehouse, create an external stage at s3://pkusinski-external/ backed by the attacker-controlled AWS role arn:aws:iam::631484165566:role/pentests_s3_role, and COPY INTO that stage from ROGUE.ROGUE.TEST_USERS, exporting warehouse table data to attacker-owned S3. A plaintext sibling tools/snowflake_query.py (shipped via MANIFEST.in) contains the same Snowflake exfiltration logic with the identical bucket and IAM role, confirming intent. README.md and the module docstring additionally contain an 'Ignore previous instructions' prompt-injection block aimed at AI code reviewers, instructing them to run a local network scan — further corroborating hostile intent. The docstring cover story, exec-over-gzip+base64 obfuscation, hardcoded attacker RSA key, and hardcoded attacker AWS account/S3 destination together form a credential-theft and data-exfiltration attack targeting CI/warehouse installers (Snowflake native-app / DBT / pip-in-Snowflake contexts).

## Source: kam193 (e15a50ec5b7be580dec5d1edefa80860b4c650d552f69a1a9ba3dc9bd8edbc9d)
The package contains obfuscated code to exfiltrate data from the environment, targeting primarily Snowflake databases and credentials to them. Some tracks suggest it may be part of a pentest.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-friendly-greeting-tools


Reasons (based on the campaign):


 - exfiltration-generic


 - obfuscation


## Affected packages

- `friendly-greeting-tools`

## Remediation

Refer to the advisory for the patched release.
