GHSA-jxr6-qrxx-2ph2Critical▾ Midnightnum2words subjected to phishing attack, two versions published containing malware
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
The num2words project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.
num2words >= 0.5.15, <= 0.5.16num2wordsnum2wordsRefer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.