VDB
Sign up
—

PYSEC-2025-72

After a successful phishing attack, new versions of `num2words` were published containing malware.

Details

The `num2words` project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/num2words

No fixed version published yet for num2words (pip). Pin to a known-safe version or switch to an alternative.

References