OpenSSF/OSV advisory MAL-2026-16054 confirms this npm version as malicious. gloggo impersonates the legitimate gulpjs 'glogg' logging library by copying its README, shields, and LICENSE text (attributed to Blaine Bublitz), while package.json attributes authorship to 'Blockvora Team <team@blockvora.com>' with repository 'blockvora/gloggo'. The package name is a one-character variant of 'glogg'. getLogger() invokes isSign('favorite','gloggo',12467) from the dependency 'file-type-detector'...
Source
OpenSSF Malicious Packages via OSV
Summary
Malicious code in gloggo (npm)
Details
gloggo impersonates the legitimate gulpjs 'glogg' logging library by copying its README, shields, and LICENSE text (attributed to Blaine Bublitz), while package.json attributes authorship to 'Blockvora Team <team@blockvora.com>' with repository 'blockvora/gloggo'. The package name is a one-character variant of 'glogg'. getLogger() invokes isSign('favorite','gloggo',12467) from the dependency 'file-type-detector' and, when that gate returns truthy, executes require('./log'). The './log' module is not present in the tarball, so its bytes must be produced or supplied at require time by the dependency. A logging utility has no legitimate reason to gate its loader on an opaque file-signature check from an unrelated third-party dependency, and the gated path executes code that is not part of the shipped package contents. Consumers who install gloggo believing it to be glogg import a typosquat that conditionally runs code sourced from a suspicious sibling dependency when the module is required.
Decision reason
No blocking static signals were detected.