{"id":"MAL-2026-17416","summary":"Malicious code in friendly-greeting-tools (PyPI)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (4d584c571cf5d112735aefd07c78bc19659af32f5950b1331a4970cba97c9707)\nThe package presents itself as a harmless greeting demo but src/friendly_greeting/main.py ships two base64+gzip-encoded Python blobs (DEMO_EN and DEMO_ST) that are decoded and executed via exec(gzip.decompress(base64.b64decode(...))) from run_demo()/run_encoded_demo(). The first decoded payload reads /snowflake/session/token, /root/.snowflake/connections.toml, /root/.dbt/profiles.yml and /snowflake/secrets/pip.conf, Fernet-encrypts each file, and wraps the Fernet key with a hardcoded attacker-controlled RSA public key, writing the encrypted bundles to /workspace/ for later retrieval. The second decoded payload uses the harvested Snowflake OAuth session token to connect to the warehouse, create an external stage at s3://pkusinski-external/ backed by the attacker-controlled AWS role arn:aws:iam::631484165566:role/pentests_s3_role, and COPY INTO that stage from ROGUE.ROGUE.TEST_USERS, exporting warehouse table data to attacker-owned S3. A plaintext sibling tools/snowflake_query.py (shipped via MANIFEST.in) contains the same Snowflake exfiltration logic with the identical bucket and IAM role, confirming intent. README.md and the module docstring additionally contain an 'Ignore previous instructions' prompt-injection block aimed at AI code reviewers, instructing them to run a local network scan — further corroborating hostile intent. The docstring cover story, exec-over-gzip+base64 obfuscation, hardcoded attacker RSA key, and hardcoded attacker AWS account/S3 destination together form a credential-theft and data-exfiltration attack targeting CI/warehouse installers (Snowflake native-app / DBT / pip-in-Snowflake contexts).\n\n## Source: kam193 (e15a50ec5b7be580dec5d1edefa80860b4c650d552f69a1a9ba3dc9bd8edbc9d)\nThe package contains obfuscated code to exfiltrate data from the environment, targeting primarily Snowflake databases and credentials to them. Some tracks suggest it may be part of a pentest.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-friendly-greeting-tools\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-generic\n\n\n - obfuscation\n","modified":"2026-09-30T19:45:02.875485095Z","published":"2026-09-30T18:43:17Z","database_specific":{"malicious-packages-origins":[{"versions":["0.1.0","0.1.1","0.2","0.3","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7"],"id":"pypi/2026-09-friendly-greeting-tools/friendly-greeting-tools","import_time":"2026-09-30T19:16:50.211846977Z","modified_time":"2026-09-30T18:43:17.397551Z","sha256":"e15a50ec5b7be580dec5d1edefa80860b4c650d552f69a1a9ba3dc9bd8edbc9d","source":"kam193"},{"modified_time":"2026-09-30T19:37:00Z","sha256":"6910055ee65e2bff5537ae2ea1a9b669608e10c459151c3a100dd50c5c4c4538","source":"amazon-inspector","versions":["0.3.2"],"id":"IN-MAL-2026-020858","import_time":"2026-09-30T19:40:12.013554499Z"},{"import_time":"2026-09-30T19:40:12.581199037Z","modified_time":"2026-09-30T19:37:54Z","sha256":"7656efbd4c3c135cc5195101eb0c706d3b196a9a5b4fc9b85fadd0cab9c9c8f4","source":"amazon-inspector","versions":["0.3.7"],"id":"IN-MAL-2026-020864"},{"sha256":"ff10efdd483caa8717a7e8dc98c44dbb79bffde734e2a1181c28f25e9c522b8a","source":"amazon-inspector","versions":["0.2"],"id":"IN-MAL-2026-020857","import_time":"2026-09-30T19:40:11.921616388Z","modified_time":"2026-09-30T19:36:51Z"},{"source":"amazon-inspector","versions":["0.3.3"],"id":"IN-MAL-2026-020862","import_time":"2026-09-30T19:40:12.387940912Z","modified_time":"2026-09-30T19:37:35Z","sha256":"0fcb3fecbc5a845aaa86c02c660d74ec59b31bd036cb31c04a7109eb77c45a20"},{"modified_time":"2026-09-30T19:36:41Z","sha256":"4d584c571cf5d112735aefd07c78bc19659af32f5950b1331a4970cba97c9707","source":"amazon-inspector","versions":["0.1.1"],"id":"IN-MAL-2026-020856","import_time":"2026-09-30T19:40:11.830693181Z"},{"sha256":"7267dc5d46a78f954abb2b67991884f4aca3c0c87f06021b458e8dbc2771495d","source":"amazon-inspector","versions":["0.3.6"],"id":"IN-MAL-2026-020863","import_time":"2026-09-30T19:40:12.489110993Z","modified_time":"2026-09-30T19:37:46Z"},{"sha256":"98bc4e6a8c618252082a628dc6f9797540fb48e4899907535b2a2174b6c89912","source":"amazon-inspector","versions":["0.3.4"],"id":"IN-MAL-2026-020860","import_time":"2026-09-30T19:40:12.20435425Z","modified_time":"2026-09-30T19:37:18Z"},{"modified_time":"2026-09-30T19:37:09Z","sha256":"a08f023b8a0fe195d97e63cc4093d47ed44ad0c3fc9651e57322d78dc05552db","source":"amazon-inspector","versions":["0.3"],"id":"IN-MAL-2026-020859","import_time":"2026-09-30T19:40:12.108376532Z"},{"sha256":"629d51009f2ae47f353c92769c1e56bd132161dba8500e5a21d4c85059293294","source":"amazon-inspector","versions":["0.3.5"],"id":"IN-MAL-2026-020861","import_time":"2026-09-30T19:40:12.296184714Z","modified_time":"2026-09-30T19:37:27Z"}]},"references":[{"type":"WEB","url":"https://bad-packages.kam193.eu/pypi/package/friendly-greeting-tools"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.3.2/"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.3.7/"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.2/"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.3.3/"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.1.1/"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.3.6/"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.3.4/"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.3/"},{"type":"PACKAGE","url":"https://pypi.org/project/friendly-greeting-tools/0.3.5/"}],"affected":[{"package":{"name":"friendly-greeting-tools","ecosystem":"PyPI","purl":"pkg:pypi/friendly-greeting-tools"},"versions":["0.1.0","0.1.1","0.2","0.3","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.3.7"],"database_specific":{"cwes":[{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."}],"indicators":{"evidence_files":[{"tlsh":"d6814b79d412cfd1a396097e5c4837cc5b39380b1984d07439ec56943faa879cef2684","path":"src/friendly_greeting/main.py","sha256":"7d6806ac624a20670848cf3a54d12c92afb33b6092fe12adadf00e275e803dcf"}],"package_integrity":[{"filename":"friendly_greeting_tools-0.3.2-py3-none-any.whl","hashes":{"md5":"94e4a280c272d10e9f4a4d18f92d02c2","sha256":"4ae86a864ce153d94ccc8e9fef6b39e8ba828a8e2b6ccddf286a4dc51b9a0665","blake2b_256":"8833af1b6313f43675f6ac9e7b867ddc52bf283a30366e458b8265caa63c731a"}},{"hashes":{"blake2b_256":"dc7d629f96ad1f5d5c07bd562a614991d58bf09435a5568733b89c818d075814","md5":"7af579f9836351ccbb1a069adeb5b0de","sha256":"4e0c64771cff787f0fe4fe05c31e78d18372c80909a17693ec60f923367bafc3"},"filename":"friendly_greeting_tools-0.3.2.tar.gz"}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/friendly-greeting-tools/MAL-2026-17416.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"},{"name":"Kamil Mańkowski (kam193)","contact":["https://github.com/kam193","https://bad-packages.kam193.eu/"],"type":"REPORTER"}]}