Anyone can register and sometimes they deliberately spam via the PM system. If you get one of these you can report the PM by clicking on the red triangle above the message. This sends a copy of the PM to the moderators and they can remove the spammers account. Then you can delete the PM.
You can also use that report function to forward sales solicitations are even hostile PMs if needed.
Since no attachments or HTML are allowed in PM's there is no risk of malware from a PM (other than the risk of major annoyance).