MAL-2025-6794
Malicious code in num2words (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: ghsa-malware (23a528edd10eb63e7c7932830fdb314983cadc840ce8ccfbaa04ad821bbdc1da) The `num2words` project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.
## Source: google-open-source-security (36822c42f7e862f29cef9734efec9a9a9cc44a80e619e954dd25c12239d15767) The num2words project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.5.15 No fixed version published yet for num2words (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nitter.tiekoetter.com/SFLinux/status/1949906299308953827 [WEB]
- https://www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise [ARTICLE]
- https://github.com/pypa/advisory-database/tree/main/vulns/num2words/PYSEC-2025-72.yaml [WEB]
- https://www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise [WEB]
- https://github.com/advisories/GHSA-jxr6-qrxx-2ph2 [ADVISORY]