{"id":"GHSA-g3j5-mpp2-2fqm","summary":"symfont/process typosquatting malware spoofs symfony/process","details":"In September 2021, security researchers discovered a malicious Composer package called `symfont/process`, a typosquat targeting users of `symfony/process`. The malicious package has since been removed from Packagist.","modified":"2023-01-26T19:53:12Z","published":"2023-01-26T19:53:11Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-01-26T19:53:11Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfont/process/2021-09-10.yaml"},{"type":"WEB","url":"https://www.kernelmode.blog/typosquatting-malware-found-in-composer-repository"}],"affected":[{"package":{"name":"symfont/process","ecosystem":"Packagist","purl":"pkg:composer/symfont/process"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-g3j5-mpp2-2fqm/GHSA-g3j5-mpp2-2fqm.json"}}],"schema_version":"1.9.0"}