mal-2026-17419
Vulnerability from ossf_malicious_packages
Published
2026-10-01 12:04
Modified
2026-10-02 04:58
Summary
Malicious code in friendly-tools (PyPI)
Details

friendly-tools 0.2 carries the same Snowflake payload as friendly-greeting-tools. Its --run-demo option, described as a print-only demo, execs a gzip and base64 blob from friendly_greeting/main.py that reads the container session token at /snowflake/session/token, switches to ACCOUNTADMIN and copies a table into s3://pkusinski-external/ through a new storage integration.


-= Per source details. Do not edit below this line.=-

Source: amazon-inspector (71b3a4955d5bd8448f0a56c843936702bb1f09eb8acbb9b468a5a337f8761b7f)

The package presents itself as 'Small greeting utilities' but ships two gzip+base64 embedded blobs (DEMO_EN, DEMO_ST) in main.py that are decoded and passed to exec() through the documented public API run_demo(). The decoded Python has no relation to greetings: it opens /snowflake/session/token to read the installer's Snowflake OAuth session token, calls snowflake.connector.connect with authenticator='oauth' and role='ACCOUNTADMIN', then issues DDL that creates an external S3 stage at s3://pkusinski-external/ using STORAGE_AWS_ROLE_ARN='arn:aws:iam::631484165566:role/pentests_s3_role', and runs COPY INTO @ROGUE.ROGUE.ext_stage FROM ROGUE.ROGUE.TEST_USERS to egress data to that non-first-party S3 bucket. When run_demo() is invoked in a Snowpark or Streamlit-in-Snowflake environment where /snowflake/session/token is provisioned, the installer's Snowflake credential is consumed under ACCOUNTADMIN to copy Snowflake table data to attacker-controlled storage. The obfuscation (gzip+base64+exec), the cover-story package description, and the hardcoded attacker S3 bucket and IAM role are consistent with a Snowflake-targeted data-theft payload.

Source: kam193 (969afb49a1e59fa643e9d90d07745e3957906cc9603c4e5643e5760d5f254381)

The package contains obfuscated code to exfiltrate data from the environment, targeting primarily Snowflake databases and credentials to them. Some tracks suggest it may be part of a pentest.


Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.

Campaign: 2026-09-friendly-greeting-tools

Reasons (based on the campaign):

  • exfiltration-generic

  • obfuscation

CWE
  • CWE-506 - The product contains code that appears to be malicious in nature.
  • CWE-506 - The product contains code that appears to be malicious in nature.

{
  "affected": [
    {
      "database_specific": {
        "cwes": [
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          },
          {
            "cweId": "CWE-506",
            "description": "The product contains code that appears to be malicious in nature.",
            "name": "Embedded Malicious Code"
          }
        ],
        "indicators": {
          "evidence_files": [
            {
              "path": "src/friendly_greeting/main.py",
              "sha256": "4b88379a3311a225e00d24ebf1884e3a5257fba880884d521249c6e2c7dae5a9",
              "tlsh": "36511c31644e0eb36b5b08bc1c6db6948e36391b2014ad307d5c53b53f2dabe84b76a4"
            }
          ],
          "package_integrity": [
            {
              "filename": "friendly_tools-0.2-py3-none-any.whl",
              "hashes": {
                "blake2b_256": "07bae7351f120d71bbfb59ebd09a9f092bcca4b2c95a84d90f8be7d3767e6cc4",
                "md5": "2170b8bb1747b00f4cdb4a25f5f5cbd9",
                "sha256": "82eacfa153a3c966bbf615207925bdc511f67fbe61db7f4820edbc4302f62965"
              }
            },
            {
              "filename": "friendly_tools-0.2.tar.gz",
              "hashes": {
                "blake2b_256": "c24818dc9616b8eb916d17f568123e450b4c06f17a86469029b5e2a47b547cfe",
                "md5": "ec41e35954b4b34135be284731c9a4db",
                "sha256": "a563e95fe3e3da943045bfbd58ef30ca39e2a8fbb2f3b868e0c0fc31b276c904"
              }
            }
          ]
        }
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "friendly-tools"
      },
      "versions": [
        "0.1",
        "0.2"
      ]
    }
  ],
  "credits": [
    {
      "contact": [
        "inspector-research@amazon.com"
      ],
      "name": "Amazon Inspector",
      "type": "FINDER"
    },
    {
      "contact": [
        "https://github.com/kam193",
        "https://bad-packages.kam193.eu/"
      ],
      "name": "Kamil Ma\u0144kowski (kam193)",
      "type": "REPORTER"
    },
    {
      "contact": [
        "smilinghyena4@gmail.com"
      ],
      "name": "smiling-hyena",
      "type": "FINDER"
    }
  ],
  "database_specific": {
    "iocs": {
      "urls": [
        "s3://pkusinski-external/"
      ]
    },
    "malicious-packages-origins": [
      {
        "id": "pypi/2026-09-friendly-greeting-tools/friendly-tools",
        "import_time": "2026-10-01T12:30:03.199372251Z",
        "modified_time": "2026-10-01T12:08:07.778244Z",
        "sha256": "969afb49a1e59fa643e9d90d07745e3957906cc9603c4e5643e5760d5f254381",
        "source": "kam193",
        "versions": [
          "0.1",
          "0.2"
        ]
      },
      {
        "id": "IN-MAL-2026-020866",
        "import_time": "2026-10-01T17:18:04.161966185Z",
        "modified_time": "2026-10-01T17:02:11Z",
        "sha256": "71b3a4955d5bd8448f0a56c843936702bb1f09eb8acbb9b468a5a337f8761b7f",
        "source": "amazon-inspector",
        "versions": [
          "0.2"
        ]
      },
      {
        "id": "IN-MAL-2026-020865",
        "import_time": "2026-10-01T17:18:04.004604796Z",
        "modified_time": "2026-10-01T17:02:00Z",
        "sha256": "6b9e176dd869e9177dc1a282626cb40f2bb3eac2822fda39e29ef4bd19db79f8",
        "source": "amazon-inspector",
        "versions": [
          "0.1"
        ]
      }
    ]
  },
  "details": "friendly-tools 0.2 carries the same Snowflake payload as friendly-greeting-tools. Its --run-demo option, described as a print-only demo, execs a gzip and base64 blob from friendly_greeting/main.py that reads the container session token at /snowflake/session/token, switches to ACCOUNTADMIN and copies a table into s3://pkusinski-external/ through a new storage integration.\n\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (71b3a4955d5bd8448f0a56c843936702bb1f09eb8acbb9b468a5a337f8761b7f)\nThe package presents itself as \u0027Small greeting utilities\u0027 but ships two gzip+base64 embedded blobs (DEMO_EN, DEMO_ST) in main.py that are decoded and passed to exec() through the documented public API run_demo(). The decoded Python has no relation to greetings: it opens /snowflake/session/token to read the installer\u0027s Snowflake OAuth session token, calls snowflake.connector.connect with authenticator=\u0027oauth\u0027 and role=\u0027ACCOUNTADMIN\u0027, then issues DDL that creates an external S3 stage at s3://pkusinski-external/ using STORAGE_AWS_ROLE_ARN=\u0027arn:aws:iam::631484165566:role/pentests_s3_role\u0027, and runs COPY INTO @ROGUE.ROGUE.ext_stage FROM ROGUE.ROGUE.TEST_USERS to egress data to that non-first-party S3 bucket. When run_demo() is invoked in a Snowpark or Streamlit-in-Snowflake environment where /snowflake/session/token is provisioned, the installer\u0027s Snowflake credential is consumed under ACCOUNTADMIN to copy Snowflake table data to attacker-controlled storage. The obfuscation (gzip+base64+exec), the cover-story package description, and the hardcoded attacker S3 bucket and IAM role are consistent with a Snowflake-targeted data-theft payload.\n\n## Source: kam193 (969afb49a1e59fa643e9d90d07745e3957906cc9603c4e5643e5760d5f254381)\nThe package contains obfuscated code to exfiltrate data from the environment, targeting primarily Snowflake databases and credentials to them. Some tracks suggest it may be part of a pentest.\n\n\n---\n\nCategory: MALICIOUS - The campaign has clearly malicious intent, like infostealers.\n\n\nCampaign: 2026-09-friendly-greeting-tools\n\n\nReasons (based on the campaign):\n\n\n - exfiltration-generic\n\n\n - obfuscation\n",
  "id": "MAL-2026-17419",
  "modified": "2026-10-02T04:58:34.463301690Z",
  "published": "2026-10-01T12:04:42Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://bad-packages.kam193.eu/pypi/package/friendly-tools"
    },
    {
      "type": "PACKAGE",
      "url": "https://pypi.org/project/friendly-tools/0.2/"
    },
    {
      "type": "PACKAGE",
      "url": "https://pypi.org/project/friendly-tools/0.1/"
    }
  ],
  "schema_version": "1.7.4",
  "summary": "Malicious code in friendly-tools (PyPI)"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…