{"id":"MAL-2026-16054","summary":"Malicious code in gloggo (npm)","details":"\n---\n_-= Per source details. Do not edit below this line.=-_\n\n## Source: amazon-inspector (a333f8ded17af0754357d938933ee95e9ab1f857cc875948d49cb9b26992e75d)\ngloggo impersonates the legitimate gulpjs 'glogg' logging library by copying its README, shields, and LICENSE text (attributed to Blaine Bublitz), while package.json attributes authorship to 'Blockvora Team \u003cteam@blockvora.com\u003e' with repository 'blockvora/gloggo'. The package name is a one-character variant of 'glogg'. getLogger() invokes isSign('favorite','gloggo',12467) from the dependency 'file-type-detector' and, when that gate returns truthy, executes require('./log'). The './log' module is not present in the tarball, so its bytes must be produced or supplied at require time by the dependency. A logging utility has no legitimate reason to gate its loader on an opaque file-signature check from an unrelated third-party dependency, and the gated path executes code that is not part of the shipped package contents. Consumers who install gloggo believing it to be glogg import a typosquat that conditionally runs code sourced from a suspicious sibling dependency when the module is required.\n","modified":"2026-09-09T01:00:04.992786283Z","published":"2026-09-09T00:16:27Z","database_specific":{"malicious-packages-origins":[{"import_time":"2026-09-09T00:47:57.934844705Z","modified_time":"2026-09-09T00:16:34Z","sha256":"4b6a7344a560f0fa4e00d334efef568cd34c3800101315a95f647dabc8285fb1","source":"amazon-inspector","versions":["1.1.3"],"id":"IN-MAL-2026-019727"},{"id":"IN-MAL-2026-019726","import_time":"2026-09-09T00:47:57.874027179Z","modified_time":"2026-09-09T00:16:27Z","sha256":"6bacf73012ce6ed828bddaf332d26ae8289b5585ea886cfc85852ac0d647282e","source":"amazon-inspector","versions":["1.1.4"]},{"import_time":"2026-09-09T00:47:58.012084713Z","modified_time":"2026-09-09T00:16:41Z","sha256":"a333f8ded17af0754357d938933ee95e9ab1f857cc875948d49cb9b26992e75d","source":"amazon-inspector","versions":["1.1.2"],"id":"IN-MAL-2026-019728"}]},"references":[{"type":"PACKAGE","url":"https://www.npmjs.com/package/gloggo/v/1.1.3"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/gloggo/v/1.1.4"},{"type":"PACKAGE","url":"https://www.npmjs.com/package/gloggo/v/1.1.2"}],"affected":[{"package":{"name":"gloggo","ecosystem":"npm","purl":"pkg:npm/gloggo"},"versions":["1.1.3","1.1.4","1.1.2"],"database_specific":{"cwes":[{"description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code","cweId":"CWE-506"},{"name":"Embedded Malicious Code","cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature."},{"cweId":"CWE-506","description":"The product contains code that appears to be malicious in nature.","name":"Embedded Malicious Code"}],"indicators":{"evidence_files":[{"tlsh":"8c21ee765af6b1536d3b74a5960e670235b9c0d7401ceb4139ece3812f68c380b76bd8","path":"index.js","sha256":"244f714c904187298d10bbef8a6df888097f7090aa8949f8c87b836549e333bd"},{"sha256":"74aeaf049db1e557f320a380b3d7a78ab3dee9b13cafde57a04e6241290b3814","tlsh":"3b110611ce789ca342d8a2ae781e02c265755d9348c9fd0cb79a530c0f5e52f64fd5ac","path":"package.json"}],"package_integrity":[{"filename":"gloggo-1.1.3.tgz","hashes":{"sha512_sri":"sha512-bgoTi37QcXFMtf6kmmq8SOJNPONIFVc1QJw2HiVG5A4l7zxBsoJ8zM2yKdML4tBZ/gnZFjNBhyCSyRPU25xRBg==","sha1":"28199903616edb2524c2e305f055bced94a2f791"}}]},"source":"https://github.com/ossf/malicious-packages/blob/main/osv/malicious/npm/gloggo/MAL-2026-16054.json"}}],"schema_version":"1.9.0","credits":[{"name":"Amazon Inspector","contact":["inspector-research@amazon.com"],"type":"FINDER"}]}