Content Quality: Well-structured News-category piece (714 words, within the 400-1200 range). Overview / What We Know / What We Don't Know / Analysis structure is used consistently with the site's format. The 'What We Don't Know' section is honest and appropriately narrow (attribution, campaign duration, and whether the wallet funds trace to this campaign are all correctly flagged as unresolved rather than speculated on). The Analysis section is clearly editorial commentary, not additional factual claims, and does not overreach beyond what the two reports support.
Source Verification: All 3 sources fetched successfully (status 200, no suspicious_patterns in manifest.json) and read in full from the gzipped snapshots on disk after independently verifying each file's sha256 against manifest.json (all three matched: source-0.html.gz 68ac39b0..., source-1.html.gz 57c904c4..., source-2.html.gz 7d0bf30c...). source-0.html.gz (checkmarx.com/zero-post, Checkmarx Zero blog, Bruno Dias, Sept 17 2026 — the primary research report): confirmed indexed-btree impersonates sorted-btree, 'almost 2 million weekly downloads', the exact code snippet showing the malicious BTree.prototype.set override calling sharedLoad.min.js, the verbatim quote 'This is a well-built way to sneak past standard taint-analysis tools and most static scanners', the Sepolia smart-contract C2 mechanism with X25519/ECDH-derived AES key decrypting a two-part second-stage payload, the Slack/Telegram exfiltration, the trace-cleanup capability, the legitimate-looking GitHub repo with populated commit history and an AI-generated profile photo, the exact list and download counts of the nine related removed packages, and the 109 ETH wallet figure. source-1.html.gz (bleepingcomputer.com, Bill Toulas, Sept 20 2026, retrieved via Archive.org fallback since the live fetch redirected through the archive but returned status 200): confirmed the same nine-package list with identical download counts, the verbatim Checkmarx quote used in the article ('The malware loader hides inside the library's own BTree.prototype.set method, which is the main function that every user would call constantly. This triggers the sharedLoad.min.js, which contains the obfuscated first stage of the malware. This is a well-built way to sneak past standard taint-analysis tools and most static scanners'), the precise claim that the loader 'executes at runtime when the application calls it with a specific key value', the npm v12 approval-mechanism bypass framing, the 109-ETH-wallet-without-confirmed-theft-link detail, and the closing advice to rotate secrets and use runtime behavioral analysis. source-2.html.gz (github.blog/changelog, June 9 2026, GitHub's official changelog): confirmed verbatim the quoted line 'npm install will no longer execute preinstall, install, or postinstall scripts from dependencies unless they are explicitly allowed in your project.' All three sources corroborate the central technical mechanism independently (two independent write-ups of the same Checkmarx research, plus GitHub's own primary description of the npm v12 behavior being evaded), so there is no single-source risk on the load-bearing technical claim.
Factual Accuracy: Every direct quote in the article appears verbatim in its cited snapshot. Every specific (download counts for indexed-btree and all nine related packages, the 109 ETH figure, the Sepolia testnet contract, X25519/ECDH/AES key-derivation chain, Slack/Telegram exfiltration) traces to at least one of the two security-research sources, most to both independently. No hallucinated figures, no invented quotes, no misattribution detected.
Overall Assessment: High-quality, precisely sourced News submission on a genuinely new npm supply-chain malware campaign. The central technical claim (malware hidden in BTree.prototype.set() bypassing npm v12's install-script blocking) was verified word-for-word against both the primary Checkmarx research and BleepingComputer's independent write-up, including the literal malicious code snippet. The internal cross-reference to the July 2026 npm v12 article was confirmed to exist and be topically accurate. No hallucinated quotes, no fabricated specifics, neutral tone, not a duplicate. The only automated flag was a source-allowlist completeness gap for a legitimate, reputable primary-source security vendor, which has been fixed at the allowlist level. Overriding script verdict from APPROVE_WITH_CORRECTIONS to APPROVE — no corrections record is warranted.