CRITICALPyPI →
num2words subjected to phishing attack, two versions published containing malware
num2words subjected to phishing attack, two versions published containing malware
Affected packages
- num2words— ≥ 0.5.15
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/ossf/malicious-packages/blob/49d0cfba3689ed9b195d101d3a2a964c6a77f767/osv/malicious/pypi/num2words/MAL-2025-6794.json
- https://github.com/pypa/advisory-database/tree/main/vulns/num2words/PYSEC-2025-72.yaml
- https://github.com/savoirfairelinux/num2words
- https://nitter.tiekoetter.com/SFLinux/status/1949906299308953827
- https://www.stepsecurity.io/blog/supply-chain-security-alert-num2words-pypi-package-shows-signs-of-compromise
Structured record: https://osv.dev/vulnerability/GHSA-jxr6-qrxx-2ph2
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta