{"id":"GHSA-g3j5-mpp2-2fqm","aliases":[],"url":"https://o3.security/vulnerability/GHSA-g3j5-mpp2-2fqm","summary":"symfont/process typosquatting malware spoofs symfony/process","details":"In September 2021, security researchers discovered a malicious Composer package called `symfont/process`, a typosquat targeting users of `symfony/process`. The malicious package has since been removed from Packagist.","published":"2023-01-26T19:53:11Z","modified":"2023-01-26T19:53:12Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"symfont/process","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/symfont/process/2021-09-10.yaml"},{"type":"WEB","url":"https://www.kernelmode.blog/typosquatting-malware-found-in-composer-repository"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-01-26T19:53:12Z"}}