Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. num2words
  4. ›
  5. GHSA-jxr6-qrxx-2ph2

GHSA-jxr6-qrxx-2ph2: num2words subjected to phishing attack, two versions published containing malware

July 31, 2025

The num2words project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.

References

  • github.com/advisories/GHSA-jxr6-qrxx-2ph2
  • github.com/pypa/advisory-database/tree/main/vulns/num2words/PYSEC-2025-72.yaml
  • github.com/savoirfairelinux/num2words
  • nitter.tiekoetter.com/SFLinux/status/1949906299308953827
  • www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise

Code Behaviors & Features

Detect and mitigate GHSA-jxr6-qrxx-2ph2 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 0.5.15 up to 0.5.16

Solution

Unfortunately, there is no solution available yet.

Weakness

  • CWE-506: Embedded Malicious Code

Source file

pypi/num2words/GHSA-jxr6-qrxx-2ph2.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 19 Aug 2025 12:19:13 +0000.