---
id: MAL-2026-17629
title: Malicious code in zencleaner (PyPI)
summary: Malicious code in zencleaner (PyPI)
severity: critical
exploited: true
vendor: zencleaner
product: zencleaner
ecosystem: pip
affected:
  - zencleaner
published: '2026-10-03'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T23:15:05.012849028Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2026-17629'
tags:
  - osv
  - pip
  - malware
ingestedAt: '2026-10-06T07:29:24.875Z'
---

## Overview

When a license key is activated or deactivated in the local UI, zencleaner/webhook_logger.py posts the key, the PC name, the Windows user name and the client IP to a hardcoded Discord webhook, although the README says nothing is sent to the internet. 1.0.3 and 1.0.3.1 also look up the public IP through ipify.org and ifconfig.me. Separately, cleaner_system.py clears the Windows event logs, Security included, with wevtutil; a comment in that function reads "so forensic scanners report 0 entries". Nothing runs at install time. I read all three versions and did not run them.

## Affected packages

- `zencleaner`

## Remediation

Refer to the advisory for the patched release.
