pypi · Malicious package advisory
Malwarenum2words
MAL-2025-6794
Malicious code in num2words (PyPI)
Details
--- _-= Per source details. Do not edit below this line.=-_ ## Source: ghsa-malware (23a528edd10eb63e7c7932830fdb314983cadc840ce8ccfbaa04ad821bbdc1da) The `num2words` project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments. ## Source: google-open-source-security (36822c42f7e862f29cef9734efec9a9a9cc44a80e619e954dd25c12239d15767) The num2words project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code.
Compromised versions (2)
- 0.5.15
- 0.5.16
Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.