{"id":"MAL-2026-17629","title":"Malicious code in zencleaner (PyPI)","summary":"Malicious code in zencleaner (PyPI)","severity":"critical","exploited":true,"vendor":"zencleaner","product":"zencleaner","ecosystem":"pip","affected":["zencleaner"],"published":"2026-10-03","updated":"2026-10-05","sourceUpdated":"2026-10-05T23:15:05.012849028Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/MAL-2026-17629","tags":["osv","pip","malware"],"ingestedAt":"2026-10-06T07:29:24.875Z","slug":"MAL-2026-17629","body":"## Overview\n\nWhen a license key is activated or deactivated in the local UI, zencleaner/webhook_logger.py posts the key, the PC name, the Windows user name and the client IP to a hardcoded Discord webhook, although the README says nothing is sent to the internet. 1.0.3 and 1.0.3.1 also look up the public IP through ipify.org and ifconfig.me. Separately, cleaner_system.py clears the Windows event logs, Security included, with wevtutil; a comment in that function reads \"so forensic scanners report 0 entries\". Nothing runs at install time. I read all three versions and did not run them.\n\n## Affected packages\n\n- `zencleaner`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"abyssal","depthScore":70,"depthScoreParts":{"impact":52.3,"likelihood":0,"exploitation":18,"ransomware":0},"changes":[]}