Closest bug reports I've found that look similar are from 2008--2009, and don't probably help here. If I were you, I'd
1) check the account settings to make sure the privacy settings are as you want them to be (I don't use Pidgin anymore, but if there's a section where you can decide who is allowed to contact you, choose something like "those I've allowed" instead of "everyone" if possible)
2) purge (remove the software along with all its configuration files, which are not necessarily removed via ordinary "remove" operation) the package(s) and reinstall
If that doesn't work, I'd simply remove the contacts completely from the list, and if they contact again, ignore them. If they kept on doing that for over a few months, I'd advice telling them to stop, do that again and then call the cops (harassment is not legal). If that didn't work, or if the message senders were not actual persons but bots or something, I'd advice getting rid of your account and creating a new one, and giving your contact information only to those you trust.
If you can't fix the thing via settings or purge+reinstallation, consider filing a new bug report to Pidgin.