Popular Python Package num2words v0.5.15 Published Without Repository Tag, Linked to Known Threat Actor
vdupras · 16h ago
What a blast from the past, I created that library, what more than a decade ago? How simpler the world was back then. This was used by nobody except us for our little shitty use case. How noisy this project has become!
arjvik · 12h ago
who currently has control over the package on PyPI? wondering how it was compromised
tardyp · 1h ago
New maintainers never bothered to change the range..
History
num2words is based on an old library, pynum2word, created by Taro Ogawa in 2003. Unfortunately, the library stopped being maintained and the author can't be reached. There was another developer, Marius Grigaitis, who in 2011 added Lithuanian support, but didn't take over maintenance of the project.
I am thus basing myself on Marius Grigaitis' improvements and re-publishing pynum2word as num2words.
I am thus basing myself on Marius Grigaitis' improvements and re-publishing pynum2word as num2words.
Virgil Dupras, Savoir-faire Linux