Back Proofpoint Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
Since at least 2022, North Korea-aligned threat actors have made a concerted effort not only to target cryptocurrency and decentralized finance organizations, but specifically to target developers using fake recruiter personas, malicious npm/PyPI packages (TraderTraitor / Jade Sleet), and trojanized cryptocurrency trading applications (AppleJeus / Citrine Sleet). These often masquerade as technical assessments or coding challenges and use techniques such as ClickFix or abusing Visual Studio Code’s features to execute malware. Approaches often occur over , Slack, Telegram, or in a multi-platform manner, with a consistent aim of targeting developer assets such as API tokens, cryptocurrency wallets, and credentials.
In April and May 2026, Proofpoint Threat Research observed a new, large wave of this type of activity distinct from known DPRK operations (also recently reported by independent researcher Denys Vitali ). Proofpoint tracks this new cluster as UNK_DeadDrop, a very likely North Korea-aligned group that uses broad phishing to target developers.
Figure 1. Distribution of UNK_DeadDrop targeting across sector and geography.
Over a six-week period, the attackers sent over 250 emails to individuals in almost 100 organizations across several sectors, primarily technology, education, business services, and financial services, specifically organizations in the cryptocurrency industry. Most targeted organizations were in the US, but the distribution of targeted geographies was global.
The emails contained links to GitHub repositories masquerading as technical assignments or cryptocurrency-related projects. The instructions encouraged the target to clone the repository and open it in an editor such as VS Code or Cursor. A pre-configured task executes silently when the user opens the repository folder in the IDE, triggering platform-specific loaders that decode embedded payloads on Linux, macOS, and Windows. The loader installs a malicious VS Code extension (VSIX) masquerading as a legitimate Google service. The payloads communicate with a hardcoded C&C server, enabling remote command execution, system reconnaissance, followed by exfiltration of browser wallet extensions, decrypted credentials, and desktop wallets. The infection chain finishes by deleting malicious payloads and directories from the cloned repository in an effort to clean up forensic artifacts, while maintaining persistence through the VSIX extension.
UNK_DeadDrop activity in late April and early May 2026 masqueraded as companies from various sectors seeking to recruit for software developer roles.
The spoofed companies included:
The emails used attacker-owned sender domains and approached targets with job opportunities for “Full-Stack Engineer” or “Agent Lead Developer” positions.
Figure 2: UNK_DeadDrop emails containing job offers for developer roles.
The emails provided instructions on how to complete a technical assignment that was part of the job application process. The URLs led to attacker-controlled GitHub repositories hosting take- assessments and coding challenges.
Campaigns observed later in May 2026 changed their approach to targets with requests for peer review on open-source projects. The attackers masqueraded as cryptocurrency trading or prediction companies, such as Pulsynk and Trixauvex, to send requests for developer code reviews with the option of a job offer based on the fixes.
Figure 3. UNK_DeadDrop emails requesting code reviews.
In late May, another UNK_DeadDrop campaign targeted finance and technology organizations requesting targets to test an ERC-4626 vault in Foundry, a toolkit for Ethereum and smart contract development.
Figure 4. UNK_DeadDrop emails requesting testing on Foundry tool.
The most recently observed iteration of UNK_DeadDrop campaigns used a project for building AI agent-based systems with payment capabilities, similarly including skill requirements and a potential job offer.
Figure 5. UNK_DeadDrop emails offering a role building an AI payments project.
Analysis of 10 repositories, all hosted by different GitHub accounts, showed four thematic categories: cryptocurrency platforms, exploit archives, Foundry testing, and AI payments.
AI-powered cryptocurrency price prediction platform
hxxps://github[.]com/Pulsynk/pulsynk
Cryptocurrency trading engine and analytics platform
hxxps://github[.]com/Trixauvex-org/trixauvex
Cross-chain blockchain exploit archive with runnable PoCs
hxxps://github[.]com/PedrinPY/rekt-db
Cross-chain blockchain exploit archive with runnable PoCs
hxxps://github[.]com/wayout4u/rekt-db
Cross-chain blockchain exploit archive with runnable PoCs
hxxps://github[.]com/Stomp47/rekt-db
forge-4626-invariants
Drop-in Foundry invariant tests for ERC-4626 vaults
hxxps://github[.]com/sr-werney/forge-4626-invariants
forge-4626-invariants
Drop-in Foundry invariant tests for ERC-4626 vaults
hxxps://github[.]com/ziobiri/forge-4626-invariants
forge-4626-invariants
Drop-in Foundry invariant tests for ERC-4626 vaults
hxxps://github[.]com/mireles343/forge-4626-invariants
HTTP 402 micropayments for AI agents - EVM, Solana, Lightning adapters
hxxps://github[.]com/skyjum/x402-kit
HTTP 402 micropayments for AI agents - EVM, Solana, Lightning adapters
hxxps://github[.]com/rkama411/x402-kit
Figure 6. UNK_DeadDrop GitHub repositories and descriptions.
The attackers presented Pulsynk and Trixauvex as AI-powered crypto prediction and trading platforms with professional Python project structures, while rekt-db masqueraded as a security research archive with reproducible proof-of-concepts for real high-profile exploits such as Bybit ($1.46B), Wormhole ($325M), and Radiant Capital ($50M). The forge-4626-invariants repository was centered around drop-in Foundry invariant tests for ERC-4626 tokenized vaults. The newest variation, x402-kit, focused on HTTP 402 micropayment infrastructure with multi-chain adapters for EVM, Solana, and Lightning networks.
The malicious repositories appeared legitimate, masquerading as open-source projects targeting specific developer niches within the cryptocurrency and blockchain ecosystem: security researchers, DeFi developers, and AI engineers. They had technical credibility, containing realistic directory structures, working npm/forge scripts, and references to real standards and frameworks.
Across 10 repositories analyzed, there were roughly six builds containing only minor changes such as binary recompilations, altered naming conventions, and bug fixes. This suggests that the operators are continuing active development.
The emails all contained GitHub or GitLab URLs with instructions to clone the repository and open it in a code editor such as VS Code or Cursor.
Figure 7. Sample attacker-controlled GitHub repository.
Inside the hidden vscode folder, there is a file called tasks.json that will execute either a shell script or .cmd file, buried in the src/ folder, when the repository is opened in Cursor or VS Code. This infection chain abuses the IDEs’ task automation as well as VSIX extensions to facilitate further execution, as well as achieve persistence on macOS and Linux devices.
The hidden tasks.json file defines a task with runOptions.runOn: "folderOpen" , a VS Code feature that executes the task automatically when the folder is opened in the editor.
Figure 8. tasks.json file that is run when .vscode folder is opened.
The task definition specifies the platform-specific commands that will be executed when the task runs:
VS Code requires user interaction before any task can run; additionally, if automatic task execution has never been accepted before, a second prompt is shown.
Figure 9. VS Code trust prompt when running malicious repository.
The launcher scripts install the VSIX extension to the editor. Every time the user opens VS Code or Cursor on macOS or Linux, the VSIX extension activates, checks whether the subsequent infection portions are already running, and re-launches them if not. On Windows, this persistence mechanism does not apply. The pipeline executes once and terminates; the VSIX remains installed but does not re-execute on subsequent editor starts.
Once the task is executed, the infection chain diverges by platform. The Linux and macOS chains use a native Go binary that connects to the C&C as a persistent RAT, while Windows runs a Node.js pipeline entirely inside the editor's Electron process. Both paths the same C&C infrastructure and exfiltration endpoints but differ significantly in their architecture and capabilities.
The Linux and macOS infection chains use native Go binaries derived from the open-source Overlord C&C framework (github[.]com/vxaboveground/Overlord). Unlike the Windows pipeline (which performs a single stealer operation), these binaries function as full RATs with persistent WebSocket connectivity.
google-update-support-linux-amd64
google-update-support-darwin-amd64
google-update-support-darwin-arm64
Figure 10. Binaries built for respective platforms.
The threat actor added three custom modules: browserlogin (Chrome and Firefox credential theft), companywallet (crypto wallet stealer with 2-phase ZIP+upload exfiltration), and cleanup (anti-forensic removal of workspace artifacts).
The initial launcher ( run-update.sh ) is a bash script with an embedded Base64-encoded payload. When executed, it installs the VSIX extension in all available editors (Cursor, VS Code, VSCodium), resolves the correct Go binary for the platform, removes macOS quarantine, and launches Overlord fully detached. It also schedules cleanup of vendor/ and .vscode/ via a background subshell that survives editor shutdown.
Figure 11. run-update.sh (Base64-decoded).
Once Overlord is running, it immediately establishes a persistent WebSocket connection to the C&C server at 23.137.105[.]75:5173 .
Figure 12. Overlord agent.log.
The credential theft chain then proceeds differently on each platform. Internally, the malware code divides its operation into two phases: Phase 1 (wallet data collection) and Phase 2 (credential theft + exfiltration). Overlord first collects wallet extension data, browser profile artifacts, and standalone wallet directories, packaging them into a ZIP and uploading to the C&C server. The malware waits five minutes before proceeding to credential theft. The credential theft uses a second embedded Mach-O binary named darwin-password-prompt that creates a fake system dialogue to prompt the user to enter their password:
Figure 13. darwin-password-prompt app showing the fake prompt.
Figure 14. Prompt for the credentials to access the keychain.
The credentials are validated by the parent Overlord process. After password validation, the malware modifies Keychain ACLs for the following browsers: Chrome, Brave, Edge, Opera, Vivaldi, Arc, Yandex, and Chromium. Safe Storage keys are then extracted. Following credential gathering, the backdoor re-launches itself as root using the captured password.
The elevated instance performs a command to dump the entire login keychain. The collected credentials, Safe Storage keys, and keychain data are then packaged as ZIP files and uploaded to the C&C via the persistent WebSocket connection.
If it is running on Linux, Overlord first collects wallet-related data (browser extension storage, standalone wallet directories) and uploads a ZIP to the C&C before attempting credential theft. After Phase 1 upload, the agent waits five minutes before proceeding to password capture. The Linux backdoor uses Zenity, a standard GTK dialog tool present on most desktop Linux distributions, to create a prompt to collect user credentials.
Figure 15. Fake dialog to collect user credentials.
This backdoor also attempts to read browser passwords from GNOME Keyring by spawning Python3 processes for each browser, querying chrome_libsecret_os_crypt_password_v2 and v1 schemas. If secret-tool is not installed, the agent falls back to the Python gi.repository.Secret method via D-Bus.
Similar to the macOS chain, Overlord re-launches itself as root using the captured password. The elevated instance re-attempts keyring access by impersonating the original user via runuser, since the GNOME Keyring is tied to the user session and not accessible directly as root. Credentials are exported to e_p.txt and uploaded as a _pa.zip to the C&C.
Unlike Linux/macOS, the Windows attack does not deploy a Go binary. It runs entirely as JavaScript inside the editor's Electron process using ELECTRON_RUN_AS_NODE=1, a documented Electron feature that turns the editor into a plain Node.js interpreter. No binary is dropped to disk, the process appears as Code.exe in Task Manager, and the editor itself provides the runtime. As stated before, the VSIX extension does not create persistence in the Windows infection chain.
The tasks.json file launches run-update-hidden-launch.vbs via wscript[.]exe //B (hidden window), which calls run-update[.]cmd .
Figure 16. run-update.cmd script.
The CMD file decodes an embedded script, which installs a VSIX extension. The script then stages three encrypted files into a staging directory and relaunches the editor with ELECTRON_RUN_AS_NODE=1 running gus-node-bootstrap.js. The three encrypted payloads are decrypted at runtime using the hardcoded AES-256-GCM key: 4f7a8c3d2e1b5f9071a6b2c8d4e3f50a92b1c7d6e8f4a30b5c2d9e1f7a6b8c4d .
windows-js-pipeline.js.enc
Runs the Node.js agent through both phases, uploads artifacts to the companywallet API, and cleans up Windows runtime files.
windows-agent-node.js.enc
Wallet stealer + Python setup
detect_malware.py.enc
DPAPI + App-Bound Encryption bypass for credential stealing
Figure 17. Windows encrypted payloads in staging directory.
The Windows variant first conducts wallet collection and then credential theft. The wallet collection is done by scanning Chromium browser variants for items in Local State, Login Data, and Local Extension Settings/, as well as wallet-specific IndexedDB entries. It targets 35 wallet extension IDs (MetaMask, Phantom, Rabby, Keplr, and others), 18 standalone wallet applications (Exodus, Electrum, Ledger Live, Monero, Solana CLI, Bitcoin, and others), and Firefox profiles. It also enumerates all Windows user profiles via registry, not just the current user.
The wallet stealer also looks for Python executables in the victim host and attempts to download Python 3.12.8 embeddable from the C&C, or falls back to system Python. If downloaded, Python is installed inside the browser's application directory (e.g., Program Files\Google\Chrome\Application\python[.]exe ) to pass App-Bound Encryption's path validation.
Once Python is available, the credential stealer ( detect_malware.py ) is executed for each browser profile. It performs:
After both phases are complete, the stolen data is uploaded to the C&C server at 23.137.105[.]75:5173 via HTTP POST. Unlike the Linux/macOS agent, the Windows pipeline does not maintain a persistent connection; it uploads the ZIP files, performs cleanup, and terminates. The VSIX package.json contains a reference to a Windows binary ( google-update-support-windows-amd64.dat ) in its description of the windowsActivationMode setting. While this binary was not found in any of the analyzed repositories, searching VirusTotal for the developer path Yuki/dionbenu2yuki returned Windows samples named google-update-support-windows-amd64[.]exe with the same C&C server and agent token found in the Linux and macOS binaries. This implies the threat actor previously distributed a Windows Go binary (Overlord RAT) but replaced it with the Node.js and Python pipeline in the current campaign, likely to avoid detection. The references to the DAT/EXE binary in the scripts are legacy code that is no longer executed.
UNK_DeadDrop campaigns spanned April and May 2026 with related infrastructure created in the same timeframe and emails sent within days of domain registrations.
Figure 18. UNK_DeadDrop domain registration timeline (April-May 2026).
Most domains were registered using Namecheap, and set MailHostBox mailservers. The domains used slight name variations of fake companies used for recruiting in phishing emails.
Some domains used to send phishing emails were also hosting unfinished, likely AI-generated websites to market the projects. These were hosted on Vercel Inc. rather than Namecheap infrastructure.
Figure 19. Fake company websites hosted at trixauvexnet[.]ink, trixauvex[.]org, and pulsnyk[.]org.
A small subset of domains, including nemesis[.]work , used Advin Services LLC IPs for hosting, which are likely attacker-controlled boxes that were also used as sender IPs in early UNK_DeadDrop campaigns: 170.205.29[.]83 and 170.205.30[.]227 . In May, the attackers transitioned to using Mailgun and MailHostBox as email sender services.
Figure 20. Fake company website spoofing NEMESIS, a decentralized finance protocol, hosted at nemesis[.]work.
UNK_DeadDrop activity shares several characteristics with previously documented North-Korea-aligned operations, specifically Contagious Interview activity reported by OpenSourceMalware , Microsoft, and JAMF . The campaigns broadly overlap in developer targeting, cryptocurrency and credential theft, GitHub delivery, VS Code workflow abuse, and cross-platform targeting.
Software developers, security researchers, AI engineers in cryptocurrency
Developers in cryptocurrency and AI
macOS, Windows, Linux
macOS, Windows, Linux
Phishing over social media
Job recruitment, code reviews
GitHub, GitLab, BitBucket
Professional structure, legitimate references, industrialized creation, iterative builds, consistent obfuscation
Possibly AI-assisted generation, less polished code, tutorial , emoji logging
VS Code tasks.json auto-execution abuse (silent)
VS Code tasks.json npm installation abuse (visible)
Malicious VSIX extension and self-contained payloads
Remote fetch from Vercel or external hosting
Overlord (Go binaries)
OtterCookie (JavaScript), Invisible Ferret (Python), FlexibleFerret (Go/Python)
WebSocket Secure (WSS)
Cryptocurrency wallets, browser credentials, system keychains
Cryptocurrency wallets, API tokens, credentials, source code, password managers
Removes payload and malicious artifacts from directories
Self-cleanup capability
Figure 20. Comparison of UNK_DeadDrop and Contagious Interview campaigns and TTPs.
However, there are several differences between the activity sets, such as the shift in social engineering from arranging fake interviews to unsolicited job offer or code review approaches as well as the move from delivery platforms such as to email. UNK_DeadDrop campaigns use the Overlord framework as a payload instead of custom malware, and it is contained within the repository rather than hosted remotely. The VS Code auto-execution approach exploits trust in standard developer workflows similar to malicious npm packages and VS code abuse, but requires less user interaction, executes silently without output, and doesn’t rely on external infrastructure that can be taken down.
It is possible, or even likely, that the overlaps between UNK_DeadDrop and Contagious Interview demonstrate an operational evolution to include more mature techniques rather than distinct but related groups. However, based on the use of email for initial access, the high volume of emails, industrialization and scale of repository creation, a new self-contained payload, and distinct infrastructure from Proofpoint observations of Contagious Interview campaigns, Proofpoint Threat Research continues to track UNK_DeadDrop activity as an independent cluster.
UNK_DeadDrop activity suggests North Korea-aligned operations targeting developers for financial gain are maturing and evolving. The shift from active social engineering over social media platforms to conduct fake interviews to large campaigns of recruitment-themed phishing emails distributing links to malicious repositories could indicate an actor industrializing and scaling operations. The consistent creation of new GitHub repositories as well as a new malware framework with iterative builds and a stealthy new execution and persistence technique through VSIX extensions demonstrates dedicated resourcing and active development of tooling. The attackers have likely also adapted by embedding payloads rather than hosting them externally, potentially increasing operational resilience and avoiding the effects of infrastructure takedowns.
UNK_DeadDrop bears many similarities to Contagious Interview activity and may be an improved and more professional iteration of operations as attackers adapt to defenders and adopt new techniques. However, the TTP and infection chain differences could also suggest another actor leveraging previously disclosed techniques or a subgroup incorporating various types of tradecraft into one operation. While attribution to a known actor remains unconfirmed, Proofpoint continues to track this ongoing activity as an independent cluster.
alex@contacttrixauvex[.]ink
Attacker-controlled email address
alex@mailpredicttogether[.]ink
Attacker-controlled email address
alex@predicttocareer[.]space
Attacker-controlled email address
Attacker-controlled email address
alex@trixauvexnet[.]ink
Attacker-controlled email address
[email protected][.]ink]
Attacker-controlled email address
[email protected][.]space
Attacker-controlled email address
[email protected][.]org
Attacker-controlled email address
[email protected][.]xyz
Attacker-controlled email address
[email protected][.]org
Attacker-controlled email address
[email protected][.]org
Attacker-controlled email address
[email protected][.]us
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]org
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]space
Attacker-controlled email address
[email protected][.]us
Attacker-controlled email address
[email protected][.]org
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]org
Attacker-controlled email address
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]space
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]ink
Attacker-controlled email address
[email protected][.]org]
Attacker-controlled email address
dalbir@empowerpharmacy[.]space
Attacker-controlled email address
dianaberendi@nxlog[.]tech
Attacker-controlled email address
gusb@ondofinance[.]tech
Attacker-controlled email address
jasen@empowerpharmacy[.]space
Attacker-controlled email address
joshc@ondofinance[.]tech
Attacker-controlled email address
Attacker-controlled email address
michaelw@ondofinance[.]tech
Attacker-controlled email address
neila@ondofinance[.]tech
Attacker-controlled email address
oladotuna@ondofinance[.]tech
Attacker-controlled email address
sarikasinha@nxlog[.]tech
Attacker-controlled email address
sladjanas@nxlog[.]tech
Attacker-controlled email address
valerie@empowerpharmacy[.]space
Attacker-controlled email address
vanjamirkovic@nxlog[.]tech
Attacker-controlled email address
Related infrastructure
Related infrastructure
deep-ai-guard[.]store
Related infrastructure
Related infrastructure
Related infrastructure
Related infrastructure
Related infrastructure
Related infrastructure
recruitptogether[.]xyz
Related infrastructure
contactpredicttogether[.]ink
Related infrastructure
connectptogether[.]ink
Related infrastructure
Related infrastructure
Related infrastructure
contacttrixauvex[.]ink
careertrixauvex[.]ink
Related infrastructure
Related infrastructure
Related infrastructure
Related infrastructure
mailpredicttogether[.]ink
predicttogetherrecruit[.]store
Related infrastructure
predicttogerecruit[.]store
Related infrastructure
predicttogether[.]ink
Related infrastructure
careerpredictto[.]space
Related infrastructure
Related infrastructure
predictcareertogether[.]space
Related infrastructure
predicttocareer[.]space
hyperdevpipline[.]org
Related infrastructure
Related infrastructure
Related infrastructure
valorecuiting[.]online
Related infrastructure
Related infrastructure
Related infrastructure
Related infrastructure
empowerpharmacy[.]space
hxxps://github[.]com/Pulsynk/pulsynk
Attacker-controlled GitHub repository
hxxps://github[.]com/Trixauvex-org/trixauvex
Attacker-controlled GitHub repository
hxxps://github[.]com/PedrinPY/rekt-db
Attacker-controlled GitHub repository
hxxps://github[.]com/sr-werney/forge-4626invariants
Attacker-controlled GitHub repository
hxxps://github[.]com/wayout4u/rekt-db
Attacker-controlled GitHub repository
hxxps://github[.]com/ziobiri/forge-4626-invariants
Attacker-controlled GitHub repository
hxxps://github[.]com/skyjum/x402-kit
Attacker-controlled GitHub repository
hxxps://github[.]com/Stomp47/rekt-db
Attacker-controlled GitHub repository
hxxps://github[.]com/mireles343/forge-4626invariants
Attacker-controlled GitHub repository
hxxps://gitlab[.]com/pulsynk-org/rekt-db.git
Attacker-controlled GitHub repository
hxxps://gitlab[.]com/trixauvex-org/x402-kit.git
Attacker-controlled GitHub repository
hxxps://gitlab[.]com/predict-together/forge-4626invariants.git
Attacker-controlled GitHub repository
hxxps://github[.]com/rkama411/x402-kit
Attacker-controlled GitHub repository
35813f4401d3ad77b618275473a556eb47bfa6f4b7439dd8943b19f81aa7252e
c935808147f0236c81483d7bbeda4b9d602f3595d5d4057f8115d39e222d1c4b
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78
run-update-hidden-launch.vbs
62761f38ed194c59abe15c49f09f0ebc431ac852c965180c9327ed84d3a454fb
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10
gus-node-bootstrap.js
91b9381d19b2e6a2db5cc0307167979b502731cb3fb50da684479e9ed35261aa
windows-agent-node.js.enc
6cf9f7b2aa456a0b438600588df869b38d8007e28f01fa96022f9d8059f120b0
windows-js-pipeline.js.enc
2812e0847d472cb8870c94f463331dbe53b84135132b9bf5f6d84c2382be628f
detect_malware.py.enc
52886aab179f26421678ff23af1b0fabf0a17ffbb534369cdbbac8008cbed8e7
google-update-support.vsix
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7e
734699773e53d995f20d485eb61261033d9d00b4332b39ca26071bcd60cd352f
e1bf1b29e6fa3525d7f32f429290a88d6ea2890e61c06574b8ff6372aa5d0667
google-update-support-agent.zip
a2b9a769df84d9d3a4694bb0252a2c6a5e5f5d1a85a04565362737092bbb3a86
google-update-support-linux-amd64
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81
google-update-support-darwin-amd64
339907b44f161f57ff30819f422c552382ff437b3ae437463b4222cfe86bd943
google-update-support-darwin-arm64
808e7154b7af2bc7a4b28d577297c55f77221c355191cbe00f9f1810b6d4a619
darwin-password-prompt
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
