---
id: MAL-2026-17419
title: Malicious code in friendly-tools (PyPI)
summary: Malicious code in friendly-tools (PyPI)
severity: critical
exploited: true
vendor: friendly-tools
product: friendly-tools
ecosystem: pip
affected:
  - friendly-tools
published: '2026-10-01'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T05:01:12.610551681Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17419'
references:
  - url: 'https://bad-packages.kam193.eu/pypi/package/friendly-tools'
  - url: 'https://pypi.org/project/friendly-tools/0.2/'
  - url: 'https://pypi.org/project/friendly-tools/0.1/'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-10-02T07:24:14.774Z'
---

## Overview

friendly-tools 0.2 carries the same Snowflake payload as friendly-greeting-tools. Its --run-demo option, described as a print-only demo, execs a gzip and base64 blob from friendly_greeting/main.py that reads the container session token at /snowflake/session/token, switches to ACCOUNTADMIN and copies a table into s3://pkusinski-external/ through a new storage integration.

---
_-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (71b3a4955d5bd8448f0a56c843936702bb1f09eb8acbb9b468a5a337f8761b7f)
The package presents itself as 'Small greeting utilities' but ships two gzip+base64 embedded blobs (DEMO_EN, DEMO_ST) in main.py that are decoded and passed to exec() through the documented public API run_demo(). The decoded Python has no relation to greetings: it opens /snowflake/session/token to read the installer's Snowflake OAuth session token, calls snowflake.connector.connect with authenticator='oauth' and role='ACCOUNTADMIN', then issues DDL that creates an external S3 stage at s3://pkusinski-external/ using STORAGE_AWS_ROLE_ARN='arn:aws:iam::631484165566:role/pentests_s3_role', and runs COPY INTO @ROGUE.ROGUE.ext_stage FROM ROGUE.ROGUE.TEST_USERS to egress data to that non-first-party S3 bucket. When run_demo() is invoked in a Snowpark or Streamlit-in-Snowflake environment where /snowflake/session/token is provisioned, the installer's Snowflake credential is consumed under ACCOUNTADMIN to copy Snowflake table data to attacker-controlled storage. The obfuscation (gzip+base64+exec), the cover-story package description, and the hardcoded attacker S3 bucket and IAM role are consistent with a Snowflake-targeted data-theft payload.

## Source: kam193 (969afb49a1e59fa643e9d90d07745e3957906cc9603c4e5643e5760d5f254381)
The package contains obfuscated code to exfiltrate data from the environment, targeting primarily Snowflake databases and credentials to them. Some tracks suggest it may be part of a pentest.


---

Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.


Campaign: 2026-09-friendly-greeting-tools


Reasons (based on the campaign):


 - exfiltration-generic


 - obfuscation


## Affected packages

- `friendly-tools`

## Remediation

Refer to the advisory for the patched release.
