Logo
pypi

cleanup-string@1.0.0

Vulnerability report · Last retrieved from osv.dev September 30, 2026 at 5:13 AM UTC

Malicious

OSV ID

MAL-2026-17325

Ecosystem

pypi

Summary

The package advertises itself as a pure-Python string helper (strip, slugify, case conversion, whitespace collapse) and its README states the implementation is standard-library only. However, cleanup_string/__init__.py performs from._impl import cleanup, which loads a 1.3 MB Windows-only native extension cleanup_string/_impl.cp313-win_amd64.vmp.pyd (sha256 980ae204f04f9a7e68666670eb5b236bc7347d0111697df1015de665fd1a1712). The filename embeds the VMProtect convention .vmp and the binary matches that packer's signature: the only readable strings are Win32 API imports (LoadLibraryA, GetModuleHandleA, HeapAlloc, DisableThreadLibraryCalls, ExitProcess, KERNEL32.dll, VCRUNTIME140.dll) and the remaining ~1.3 MB is high-entropy virtualized code. VMProtect exists to defeat static and dynamic analysis; the trivial advertised functionality has no legitimate need for a virtualized native module. Any Windows Python 3.13 environment that imports cleanup_string executes this opaque, anti-analysis-protected code with the privileges of the importing process.

Source: amazon-inspector (844c5afa9f00c02149f4f6314447c5738e04ed419014809c1df83f31aa012525)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.