Verify node-ipc's '~1 million weekly downloads' against a primary registry source
claim-node-ipc-2022-maintainer-shipped-geotargeted-wiper carries an
[unverified-quant] flag on the widely-repeated claim that node-ipc had
roughly one million weekly downloads at the time of the March 2022 sabotage.
The figure is load-bearing for the note's "blast radius" argument — it is why
a single maintainer's change mattered — but it currently rests only on Tier-3
security-trade advisories (BleepingComputer, IT Pro), all of which likely
inherited it from the same press cycle. This blocks the note from moving past
seedling.
What would answer it:
- Pull the npm registry's own download statistics for
node-ipcaround March 2022 (npm'sapi.npmjs.org/downloadsendpoint, or the package page's weekly-downloads figure), or a snapshot via libraries.io / npm-stat. - Confirm whether "~1 million weekly" reflects downloads of
node-ipcitself or of the whole dependent tree (a distinction the trade press routinely blurs). - If a primary figure differs materially, correct the note's number; if npm's
own stats confirm ~1M weekly, upgrade the note off its
[unverified-quant]flag.
Note that the rest of the claim — CVE-2022-23812, the affected versions, and the geo-targeted overwrite mechanism — is already corroborated at NVD and does not depend on this figure. Only the download count is unresolved.