GHSA-jxr6-qrxx-2ph2
Dashboard / Vulnerabilities / GHSA-jxr6-qrxx-2ph2
GHSA-jxr6-qrxx-2ph2
Summary: num2words subjected to phishing attack, two versions published containing malware
Details: The `num2words` project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.
References: https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/num2words/MAL-2025-6794.json, https://github.com/pypa/advisory-database/tree/main/vulns/num2words/PYSEC-2025-72.yaml, https://github.com/savoirfairelinux/num2words, https://nitter.tiekoetter.com/SFLinux/status/1949906299308953827, https://www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise
Affected packages
Package
Name: num2words
Purl: pkg:pypi/num2words
Affected ranges
Type: ECOSYSTEM
Events:
