Vulnerability MAL-2026-17629

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 days ago
October 03, 2026 at 10:47 PM UTC
Malicious code in zencleaner (PyPI)
1.0.0 and 1.0.3 - 1.0.3.1
1.0.0 and 1.0.3 - 1.0.3.1

Summary

Malicious code in zencleaner (PyPI)

Details

When a license key is activated or deactivated in the local UI, zencleaner/webhook_logger.py posts the key, the PC name, the Windows user name and the client IP to a hardcoded Discord webhook, although the README says nothing is sent to the internet. 1.0.3 and 1.0.3.1 also look up the public IP through ipify.org and ifconfig.me. Separately, cleaner_system.py clears the Windows event logs, Security included, with wevtutil; a comment in that function reads "so forensic scanners report 0 entries". Nothing runs at install time. I read all three versions and did not run them.

Impacted packages

Timeline

Published
2 days ago
October 03, 2026 at 10:47 PM UTC
Last Modified
8 hours ago
October 05, 2026 at 11:15 PM UTC