MAL-2026-17325Critical▾ Abyssal⚠ Exploited in the wildMalicious code in cleanup-string (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
-= Per source details. Do not edit below this line.=-
The package advertises itself as a pure-Python string helper (strip, slugify, case conversion, whitespace collapse) and its README states the implementation is standard-library only. However, cleanup_string/__init__.py performs from._impl import cleanup, which loads a 1.3 MB Windows-only native extension cleanup_string/_impl.cp313-win_amd64.vmp.pyd (sha256 980ae204f04f9a7e68666670eb5b236bc7347d0111697df1015de665fd1a1712). The filename embeds the VMProtect convention .vmp and the binary matches that packer's signature: the only readable strings are Win32 API imports (LoadLibraryA, GetModuleHandleA, HeapAlloc, DisableThreadLibraryCalls, ExitProcess, KERNEL32.dll, VCRUNTIME140.dll) and the remaining ~1.3 MB is high-entropy virtualized code. VMProtect exists to defeat static and dynamic analysis; the trivial advertised functionality has no legitimate need for a virtualized native module. Any Windows Python 3.13 environment that imports cleanup_string executes this opaque, anti-analysis-protected code with the privileges of the importing process.
cleanup-stringRefer to the advisory for the patched release.