---
id: GHSA-jxr6-qrxx-2ph2
aliases:
  - MAL-2025-6794
  - PYSEC-2025-72
title: >-
  num2words subjected to phishing attack, two versions published containing
  malware
summary: >-
  num2words subjected to phishing attack, two versions published containing
  malware
severity: critical
vendor: num2words
product: num2words
ecosystem: pip
affected:
  - 'num2words >= 0.5.15, <= 0.5.16'
  - num2words
  - num2words
published: '2025-07-31'
updated: '2026-07-30'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-jxr6-qrxx-2ph2'
references:
  - url: >-
      https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/num2words/MAL-2025-6794.json
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/num2words/PYSEC-2025-72.yaml
  - url: 'https://github.com/savoirfairelinux/num2words'
  - url: 'https://nitter.tiekoetter.com/SFLinux/status/1949906299308953827'
  - url: >-
      https://www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise
tags:
  - osv
  - pip
ingestedAt: '2026-07-30T19:09:51.214Z'
---

## Overview

The `num2words` project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.

## Affected packages

- `num2words >= 0.5.15, <= 0.5.16`
- `num2words`
- `num2words`

## Remediation

Refer to the advisory for the patched release.
