---
title: "Verify node-ipc's '~1 million weekly downloads' against a primary registry source"
type: "question"
status: "open"
date_raised: "2026-07-11T00:00:00.000Z"
tags: ["node-ipc","npm","protestware","software-supply-chain","verification","quant"]
---


[[claim-node-ipc-2022-maintainer-shipped-geotargeted-wiper]] carries an
`[unverified-quant]` flag on the widely-repeated claim that `node-ipc` had
roughly one million weekly downloads at the time of the March 2022 sabotage.
The figure is load-bearing for the note's "blast radius" argument — it is why
a single maintainer's change mattered — but it currently rests only on Tier-3
security-trade advisories (BleepingComputer, IT Pro), all of which likely
inherited it from the same press cycle. This blocks the note from moving past
`seedling`.

**What would answer it:**

- Pull the npm registry's own download statistics for `node-ipc` around
  March 2022 (npm's `api.npmjs.org/downloads` endpoint, or the package page's
  weekly-downloads figure), or a snapshot via libraries.io / npm-stat.
- Confirm whether "~1 million weekly" reflects downloads of `node-ipc` itself
  or of the whole dependent tree (a distinction the trade press routinely
  blurs).
- If a primary figure differs materially, correct the note's number; if npm's
  own stats confirm ~1M weekly, upgrade the note off its `[unverified-quant]`
  flag.

Note that the *rest* of the claim — CVE-2022-23812, the affected versions, and
the geo-targeted overwrite mechanism — is already corroborated at NVD and does
not depend on this figure. Only the download count is unresolved.
