MAL-2025-6794None▾ SunlitMalicious code in num2words (PyPI)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
-= Per source details. Do not edit below this line.=-
The num2words project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.
The num2words project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code.
num2words >= 0.5.15, <= 0.5.16Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.