VYPR

pypi · Malicious package advisory

Malware

num2words

PYSEC-2025-72

After a successful phishing attack, new versions of `num2words` were published containing malware.

Details

The `num2words` project was compromised via a phishing attack
and two new versions were uploaded to PyPI containing malicious code.
The affected versions have been removed from PyPI,
and users are advised to remove the affected versions from their environments.

Compromised versions (2)

  • 0.5.15
  • 0.5.16

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.