pypi
Maliciousfriendly-tools@0.2
Vulnerability report · Last retrieved from osv.dev October 1, 2026 at 3:20 PM UTC
OSV ID
MAL-2026-17419
Ecosystem
pypi
Summary
The package contains obfuscated code to exfiltrate data from the environment, targeting primarily Snowflake databases and credentials to them. Some tracks suggest it may be part of a pentest. --- Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2026-09-friendly-greeting-tools Reasons (based on the campaign): - exfiltration-generic - obfuscation
Source: kam193 (969afb49a1e59fa643e9d90d07745e3957906cc9603c4e5643e5760d5f254381)
Protect your entire dependency tree
Scan your lock files automatically on every PR. Block malicious packages before they reach production.