{"id":"PYSEC-2025-72","summary":"After a successful phishing attack, new versions of `num2words` were published containing malware.","details":"The `num2words` project was compromised via a phishing attack\nand two new versions were uploaded to PyPI containing malicious code.\nThe affected versions have been removed from PyPI,\nand users are advised to remove the affected versions from their environments.\n","aliases":["GHSA-jxr6-qrxx-2ph2","MAL-2025-6794"],"modified":"2025-08-06T04:27:26.046626Z","published":"2025-07-31T14:34:47Z","references":[{"type":"EVIDENCE","url":"https://nitter.tiekoetter.com/SFLinux/status/1949906299308953827"},{"type":"EVIDENCE","url":"https://www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise"}],"affected":[{"package":{"name":"num2words","ecosystem":"PyPI","purl":"pkg:pypi/num2words"},"versions":["0.5.15","0.5.16"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/num2words/PYSEC-2025-72.yaml"}}],"schema_version":"1.7.5","credits":[{"name":"Mike Fiedler","type":"COORDINATOR"}]}