MAL-2026-17629Critical▾ Abyssal⚠ Exploited in the wildMalicious code in zencleaner (PyPI)
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 52.3 · likelihood 0 · exploitation 18
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
When a license key is activated or deactivated in the local UI, zencleaner/webhook_logger.py posts the key, the PC name, the Windows user name and the client IP to a hardcoded Discord webhook, although the README says nothing is sent to the internet. 1.0.3 and 1.0.3.1 also look up the public IP through ipify.org and ifconfig.me. Separately, cleaner_system.py clears the Windows event logs, Security included, with wevtutil; a comment in that function reads "so forensic scanners report 0 entries". Nothing runs at install time. I read all three versions and did not run them.
zencleanerRefer to the advisory for the patched release.