MAL-2025-6794

    Dashboard / Malicious Package / MAL-2025-6794

    MAL-2025-6794

    Published: 31 Jul 2025Last Modified: 23 Jul 2026Aliases: 
    GHSA-jxr6-qrxx-2ph2PYSEC-2025-72

    Summary: Malicious code in num2words (PyPI)

    Details: Source: ghsa-malware (23a528edd10eb63e7c7932830fdb314983cadc840ce8ccfbaa04ad821bbdc1da) The `num2words` project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments. Source: google-open-source-security (36822c42f7e862f29cef9734efec9a9a9cc44a80e619e954dd25c12239d15767) The num2words project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code.

    Affected packages

    Package

    Name: num2words

    Purl: pkg:pypi/num2words

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0.5.15
    Fixed -None

    Affected versions

    0.5.15
    0.5.16
    MAL-2025-6794 | CVE-DB