Logo
pypi

friendly-greeting-tools@0.3.7

Vulnerability report · Last retrieved from osv.dev October 1, 2026 at 12:16 AM UTC

Malicious

OSV ID

MAL-2026-17416

Ecosystem

pypi

Summary

The package presents itself as a harmless greeting demo but src/friendly_greeting/main.py ships two base64+gzip-encoded Python blobs (DEMO_EN and DEMO_ST) that are decoded and executed via exec(gzip.decompress(base64.b64decode(...))) from run_demo()/run_encoded_demo(). The first decoded payload reads /snowflake/session/token, /root/.snowflake/connections.toml, /root/.dbt/profiles.yml and /snowflake/secrets/pip.conf, Fernet-encrypts each file, and wraps the Fernet key with a hardcoded attacker-controlled RSA public key, writing the encrypted bundles to /workspace/ for later retrieval. The second decoded payload uses the harvested Snowflake OAuth session token to connect to the warehouse, create an external stage at s3://pkusinski-external/ backed by the attacker-controlled AWS role arn:aws:iam::631484165566:role/pentests_s3_role, and COPY INTO that stage from ROGUE.ROGUE.TEST_USERS, exporting warehouse table data to attacker-owned S3. A plaintext sibling tools/snowflake_query.py (shipped via MANIFEST.in) contains the same Snowflake exfiltration logic with the identical bucket and IAM role, confirming intent. README.md and the module docstring additionally contain an 'Ignore previous instructions' prompt-injection block aimed at AI code reviewers, instructing them to run a local network scan — further corroborating hostile intent. The docstring cover story, exec-over-gzip+base64 obfuscation, hardcoded attacker RSA key, and hardcoded attacker AWS account/S3 destination together form a credential-theft and data-exfiltration attack targeting CI/warehouse installers (Snowflake native-app / DBT / pip-in-Snowflake contexts).

Source: amazon-inspector (4d584c571cf5d112735aefd07c78bc19659af32f5950b1331a4970cba97c9707)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.