num2words subjected to phishing attack, two versions published containing malware
Critical severity
GitHub Reviewed
Published
Jul 31, 2025
to the GitHub Advisory Database
•
Updated Jul 31, 2025
Description
Published to the GitHub Advisory Database
Jul 31, 2025
Reviewed
Jul 31, 2025
Last updated
Jul 31, 2025
The
num2words
project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.References