---
id: MAL-2025-6794
aliases:
  - GHSA-jxr6-qrxx-2ph2
  - PYSEC-2025-72
title: Malicious code in num2words (PyPI)
summary: Malicious code in num2words (PyPI)
severity: none
vendor: num2words
product: num2words
ecosystem: pip
affected:
  - 'num2words >= 0.5.15, <= 0.5.16'
published: '2025-07-31'
updated: '2026-07-23'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/MAL-2025-6794'
references:
  - url: 'https://nitter.tiekoetter.com/SFLinux/status/1949906299308953827'
  - url: >-
      https://www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/num2words/PYSEC-2025-72.yaml
  - url: >-
      https://www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise
  - url: 'https://github.com/advisories/GHSA-jxr6-qrxx-2ph2'
tags:
  - osv
  - pip
ingestedAt: '2026-07-23T19:05:52.021Z'
---

## Overview


---
_-= Per source details. Do not edit below this line.=-_

## Source: ghsa-malware (23a528edd10eb63e7c7932830fdb314983cadc840ce8ccfbaa04ad821bbdc1da)
The `num2words` project was compromised via a phishing attack and two new versions were uploaded to PyPI containing malicious code. The affected versions have been removed from PyPI, and users are advised to remove the affected versions from their environments.

## Source: google-open-source-security (36822c42f7e862f29cef9734efec9a9a9cc44a80e619e954dd25c12239d15767)
The num2words project was compromised via a phishing attack and two new
versions were uploaded to PyPI containing malicious code.


## Affected packages

- `num2words >= 0.5.15, <= 0.5.16`

## Remediation

Refer to the advisory for the patched release.
