MAL-2026-17629

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/zencleaner/MAL-2026-17629.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2026-17629
Published
2026-10-03T22:47:45Z
Modified
2026-10-05T23:15:05Z
Summary
Malicious code in zencleaner (PyPI)
Details

When a license key is activated or deactivated in the local UI, zencleaner/webhook_logger.py posts the key, the PC name, the Windows user name and the client IP to a hardcoded Discord webhook, although the README says nothing is sent to the internet. 1.0.3 and 1.0.3.1 also look up the public IP through ipify.org and ifconfig.me. Separately, cleaner_system.py clears the Windows event logs, Security included, with wevtutil; a comment in that function reads "so forensic scanners report 0 entries". Nothing runs at install time. I read all three versions and did not run them.

Database specific
{
    "iocs":  {
        "urls":  [
            "https://discord.com/api/webhooks/1555423493796012102"
        ]
    }
}
Credits

Affected packages

PyPI / zencleaner

Package

Name
zencleaner
View open source insights on deps.dev
Purl
pkg:pypi/zencleaner

Affected ranges

Affected versions

1.*
1.0.0
1.0.3
1.0.3.1

Database specific

source
"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/pypi/zencleaner/MAL-2026-17629.json"