{"_id":"@dhanushnehru/lockcheck","_rev":"3-7f88bd8e28f7af07a17a829a40aa7645","name":"@dhanushnehru/lockcheck","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@dhanushnehru/lockcheck","version":"1.0.0","keywords":["security","npm","supply-chain","lockfile","audit","dependencies","cli","devops","cybersecurity","package-lock"],"author":{"url":"https://github.com/DhanushNehru","name":"Dhanush Nehru","email":"hello@dhanushnehru.com"},"license":"MIT","_id":"@dhanushnehru/lockcheck@1.0.0","maintainers":[{"name":"dhanushnehru","email":"dhanushxenocrate@gmail.com"}],"homepage":"https://github.com/DhanushNehru/lockcheck#readme","bugs":{"url":"https://github.com/DhanushNehru/lockcheck/issues"},"bin":{"lockcheck":"bin/lockcheck.js"},"dist":{"shasum":"72058e752a1a7bf7a5e11ff458fffc6f5ee4b420","tarball":"https://registry.npmjs.org/@dhanushnehru/lockcheck/-/lockcheck-1.0.0.tgz","fileCount":18,"integrity":"sha512-loeqKNIL5G0NSJIErGSZT61GSna2B/TVkm35HfiKSyMzzbt2eCaFl2/Y3BoAS9Pu/wycn6fhmhB7OoFaoPmESA==","signatures":[{"sig":"MEUCIQD/BOvY4GzRlJs9odDRSSFO7ObyfNJR80kxTM42j41HvQIgYtHQ3i++PgLBwQzmTLXvRGdzjFe/HYwefQ/5bT7oB1E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":57282},"main":"src/index.js","type":"module","engines":{"node":">=18.0.0"},"gitHead":"f81d02cdcfc2b4ad6f6f128478ffa42f83056c4f","scripts":{"test":"node bin/lockcheck.js --json","start":"node bin/lockcheck.js"},"_npmUser":{"name":"dhanushnehru","email":"dhanushxenocrate@gmail.com"},"repository":{"url":"git+https://github.com/DhanushNehru/lockcheck.git","type":"git"},"_npmVersion":"11.6.2","description":"Detect malicious dependency diffs in lock files. Catches supply chain attacks before they catch you.","directories":{},"_nodeVersion":"24.11.1","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/lockcheck_1.0.0_1775301442843_0.8653882029141751","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@dhanushnehru/lockcheck","version":"1.0.1","keywords":["security","npm","supply-chain","lockfile","audit","dependencies","cli","devops","cybersecurity","package-lock"],"author":{"url":"https://github.com/DhanushNehru","name":"Dhanush Nehru","email":"hello@dhanushnehru.com"},"license":"MIT","_id":"@dhanushnehru/lockcheck@1.0.1","maintainers":[{"name":"dhanushnehru","email":"dhanushxenocrate@gmail.com"}],"homepage":"https://github.com/DhanushNehru/lockcheck#readme","bugs":{"url":"https://github.com/DhanushNehru/lockcheck/issues"},"bin":{"lockcheck":"bin/lockcheck.js"},"dist":{"shasum":"eaae8909acfbae4816ef1029c2dcf5aa036df2a9","tarball":"https://registry.npmjs.org/@dhanushnehru/lockcheck/-/lockcheck-1.0.1.tgz","fileCount":18,"integrity":"sha512-L7QTOzVKRYUq+0D49qTSLkCtWsR4IwNwJD5siz89pCF9fptK2pArN1SfTSIFZkX7Evqmypl68CrL4v974pJdmw==","signatures":[{"sig":"MEQCIAbDbq/Emzv+yppiCi+jhHYyoeo9xewog98q/1jwL/xyAiBb4nieQBO9tsRSYaBJpph1LJsEIyHlwyVNzDRPEcQMPA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCJTK3eQ0NwheHcXLKKsvBHVaLPXzZcCuqXHnALSziCsQIgaDhNDmogSoEqI4fTjoHCOBIjxPHwbEqLuiR85L1//Ws=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":60106},"main":"src/index.js","type":"module","engines":{"node":">=18"},"gitHead":"05483cf4ac25004083bf6374f4837bffa8fb8479","scripts":{"test":"node bin/lockcheck.js --json","start":"node bin/lockcheck.js"},"_npmUser":{"name":"dhanushnehru","email":"dhanushxenocrate@gmail.com"},"repository":{"url":"git+https://github.com/DhanushNehru/lockcheck.git","type":"git"},"_npmVersion":"11.19.0","description":"Detect malicious dependency diffs in lock files. Catches supply chain attacks before they catch you.","directories":{},"_nodeVersion":"24.21.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/lockcheck_1.0.1_1789986948001_0.1494155222871505","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"_id":"@dhanushnehru/lockcheck@1.0.2","bin":{"lockcheck":"bin/lockcheck.js"},"bugs":{"url":"https://github.com/DhanushNehru/lockcheck/issues"},"dist":{"shasum":"7fd50f2a039b8eac871ee650cb0f0b662d73662c","tarball":"https://registry.npmjs.org/@dhanushnehru/lockcheck/-/lockcheck-1.0.2.tgz","fileCount":18,"integrity":"sha512-BqEH1is0y1lKVRKfGdrTybR7VWwdWn6sPGAX7a6jUJhUI53bS6JTBDqpcrWRbt7T55BW6zq35XhGwDrpvTmmIQ==","signatures":[{"sig":"MEQCIFWosFmNuoh3b7CPUo/zQr13A0SBGfOK5hDrC0igO7VsAiBAvNaeqLgZYehOcpv1Mre6Tb9HtK2SOtSfj2TwFasOKA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDDD6xa0bfNFRs5MaGOB7ZJwDZy0AATJSyKoiEkPTyYgAIgRlk1Qj8HJBC8zn8DN90xNrBDz4DLXHlXcku6UeH1mko="}],"unpackedSize":60359},"main":"src/index.js","name":"@dhanushnehru/lockcheck","type":"module","author":{"url":"https://github.com/DhanushNehru","name":"Dhanush Nehru","email":"hello@dhanushnehru.com"},"engines":{"node":">=18"},"gitHead":"76138030f5afad8528407746a566b4c345a14d49","license":"MIT","scripts":{"test":"node bin/lockcheck.js --json","start":"node bin/lockcheck.js"},"version":"1.0.2","_npmUser":{"name":"dhanushnehru","email":"dhanushxenocrate@gmail.com"},"homepage":"https://github.com/DhanushNehru/lockcheck#readme","keywords":["security","npm","supply-chain","lockfile","audit","dependencies","cli","devops","cybersecurity","package-lock"],"repository":{"url":"git+https://github.com/DhanushNehru/lockcheck.git","type":"git"},"_npmVersion":"11.19.0","description":"Detect malicious dependency diffs in lock files. Catches supply chain attacks before they catch you.","directories":{},"maintainers":[{"name":"dhanushnehru","email":"dhanushxenocrate@gmail.com"}],"_nodeVersion":"24.21.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/lockcheck_1.0.2_1790840452275_0.8644908517261873"}}},"time":{"created":"2026-04-04T11:17:22.745Z","modified":"2026-10-01T07:40:52.528Z","1.0.0":"2026-04-04T11:17:23.029Z","1.0.1":"2026-09-21T10:35:48.068Z","1.0.2":"2026-10-01T07:40:52.370Z"},"bugs":{"url":"https://github.com/DhanushNehru/lockcheck/issues"},"author":{"url":"https://github.com/DhanushNehru","name":"Dhanush Nehru","email":"hello@dhanushnehru.com"},"license":"MIT","homepage":"https://github.com/DhanushNehru/lockcheck#readme","keywords":["security","npm","supply-chain","lockfile","audit","dependencies","cli","devops","cybersecurity","package-lock"],"repository":{"url":"git+https://github.com/DhanushNehru/lockcheck.git","type":"git"},"description":"Detect malicious dependency diffs in lock files. Catches supply chain attacks before they catch you.","maintainers":[{"name":"dhanushnehru","email":"dhanushxenocrate@gmail.com"}],"readme":"<div align=\"center\">\n\n# 🔒 lockcheck\n\n**Detect malicious dependency diffs in lock files.**\nCatches supply chain attacks before they catch you.\n\n[![npm version](https://img.shields.io/npm/v/@dhanushnehru/lockcheck.svg?style=flat-square&color=cb3837)](https://www.npmjs.com/package/@dhanushnehru/lockcheck)\n[![license](https://img.shields.io/badge/license-MIT-blue.svg?style=flat-square)](LICENSE)\n[![GitHub stars](https://img.shields.io/github/stars/DhanushNehru/lockcheck?style=flat-square&color=yellow)](https://github.com/DhanushNehru/lockcheck/stargazers)\n[![zero deps](https://img.shields.io/badge/dependencies-0-brightgreen?style=flat-square)](package.json)\n[![Node.js](https://img.shields.io/badge/node-%3E%3D18-brightgreen?style=flat-square)](package.json)\n\n</div>\n\n---\n\nEvery time you run `npm install`, your lockfile changes. **Nobody reviews those diffs.** Attackers exploit this by injecting typosquatted, hijacked, or backdoored packages.\n\n`lockcheck` scans your `package-lock.json`, diffs it against a saved snapshot, and flags anything suspicious — **before it reaches production**.\n\n## ⚡ Quick Start\n\n```bash\nnpx @dhanushnehru/lockcheck\n```\n\nThat's it. No install required. No configuration. No dependencies.\n\n## 🔍 What It Detects\n\n```\n┌────────────────────────────────────────────────────┐\n│ 🔒 lockcheck                                       │\n│ Supply chain security scanner for lock files       │\n└────────────────────────────────────────────────────┘\n\n  🔴 CRITICAL\n  ────────────────────────────────────────────────────\n  🔴 ev4l-js @1.0.0\n    Possible typosquat of \"eval-js\" (edit distance 1)\n    Levenshtein distance: 1\n\n  🔴 lodash @4.99.0\n    Integrity hash changed without version change!\n    This could indicate the package was republished.\n\n  ⚠️  WARNINGS\n  ────────────────────────────────────────────────────\n  ⚠️  sketchy-lib @1.0.0\n    New dependency added: sketchy-lib@1.0.0\n    (production dependency)\n\n  ⚠️  sketchy-lib @1.0.0\n    Published 2 day(s) ago\n    New packages should be reviewed carefully.\n\n  ⚠️  sketchy-lib @1.0.0\n    Very low download count: 47 weekly downloads\n    Low-download packages are higher risk.\n\n  ⚠️  random-helper @2.0.0\n    Has install scripts (preinstall/install/postinstall)\n    Install scripts can execute arbitrary code.\n\n┌────────────────────────────────────────────────────┐\n│  📦 847 packages scanned                           │\n│  🆕 3 new dependencies                             │\n│  → 12 version changes                              │\n├────────────────────────────────────────────────────┤\n│  🔴 2 critical                                     │\n│  ⚠️  4 warning(s)                                  │\n└────────────────────────────────────────────────────┘\n```\n\n## 🛡️ 6 Security Analyzers\n\n| Analyzer | What It Catches |\n|----------|----------------|\n| **New Dependencies** | Packages added since last scan — the primary attack vector |\n| **Version Jumps** | Suspicious semver changes: 4.17.21 → 4.99.0, downgrades |\n| **Typosquat Detection** | Names similar to popular packages: `1odash`, `reqest`, `epress` |\n| **Registry Anomalies** | Non-standard registries, registry switches, integrity hash changes |\n| **Install Scripts** | Packages with `postinstall` scripts (primary code execution vector) |\n| **Freshness Checks** | Newly published packages with low downloads (via npm registry API) |\n\n## 📖 Usage\n\n```bash\n# Scan current directory\nnpx @dhanushnehru/lockcheck\n\n# Scan a specific project\nnpx @dhanushnehru/lockcheck ./my-app\n\n# CI/CD mode (JSON output + strict exit codes)\nnpx @dhanushnehru/lockcheck --json --strict\n\n# Offline mode (skip npm registry checks)\nnpx @dhanushnehru/lockcheck --no-network\n\n# Show help\nnpx @dhanushnehru/lockcheck --help\n```\n\n## 🏗️ How It Works\n\n1. **Parse** — Reads your `package-lock.json` (supports lockfileVersion 1, 2, and 3)\n2. **Snapshot** — Compares against a saved `.lockcheck-snapshot.json` baseline\n3. **Analyze** — Runs 6 independent security analyzers\n4. **Report** — Outputs findings with severity levels (critical/warning/info)\n5. **Exit** — Returns code `0` (safe) or `1` (issues found) for CI integration\n\nOn first run, lockcheck creates a baseline snapshot. On subsequent runs, it diffs against that baseline to detect changes.\n\n## 🤖 GitHub Action\n\nAdd lockcheck to your CI pipeline to automatically scan every PR:\n\n```yaml\n# .github/workflows/lockcheck.yml\nname: Lockfile Security\n\non:\n  pull_request:\n    paths:\n      - 'package-lock.json'\n\njobs:\n  lockcheck:\n    runs-on: ubuntu-latest\n    steps:\n      - uses: actions/checkout@v4\n      - uses: DhanushNehru/lockcheck@v1\n        with:\n          strict: true\n```\n\nOr use it directly:\n\n```yaml\n- name: Run lockcheck\n  run: npx @dhanushnehru/lockcheck --strict\n```\n\n## 🔧 Options\n\n| Flag | Description |\n|------|-------------|\n| `--json` | Output results as JSON for CI/CD pipelines |\n| `--strict` | Exit with code 1 on warnings (not just criticals) |\n| `--no-network` | Skip npm registry API checks (offline mode) |\n| `--help, -h` | Show help message |\n| `--version, -v` | Show version number |\n\n## 💡 Exit Codes\n\n| Code | Meaning |\n|------|---------|\n| `0` | No critical issues found |\n| `1` | Critical issues detected (or warnings in `--strict` mode) |\n| `2` | Runtime error (missing lockfile, etc.) |\n\n## 🕵️ Why lockcheck?\n\n### The Problem\nSupply chain attacks on npm have exploded:\n- **Typosquatting** — Packages named `1odash`, `angu1ar`, `reqest` that execute malicious code\n- **Package hijacking** — Maintainer accounts get compromised, legit packages get backdoored\n- **Dependency confusion** — Private package names are registered on the public registry\n- **Postinstall payloads** — Malicious code runs immediately on `npm install`\n\n### What Exists Today\n- `npm audit` only checks **known CVEs** — it doesn't catch zero-day supply chain attacks\n- Lock file diffs are **thousands of lines** that no human reviews\n- CI pipelines auto-merge Dependabot PRs with **zero lockfile inspection**\n\n### What lockcheck Does Differently\n- **Proactive detection** — Catches suspicious patterns before they become CVEs\n- **Zero dependencies** — Eats its own dogfood. Nothing to get supply-chain attacked through.\n- **Snapshot diffing** — Tracks changes over time instead of point-in-time scanning\n- **Smart heuristics** — Typosquat detection, version jump analysis, registry anomaly detection\n\n## 🏛️ Architecture\n\n```\nlockcheck/\n├── bin/lockcheck.js          # CLI entry point\n├── src/\n│   ├── index.js              # Scan orchestrator\n│   ├── parsers/npm.js        # package-lock.json parser\n│   ├── analyzers/            # 6 independent security analyzers\n│   ├── reporters/terminal.js # Beautiful terminal output\n│   └── utils/                # Colors, semver, levenshtein, registry\n├── action.yml                # GitHub Action\n└── package.json              # Zero dependencies\n```\n\n## 🤝 Contributing\n\nContributions are welcome! See [CONTRIBUTING.md](CONTRIBUTING.md) for guidelines.\n\n**Adding a new analyzer is easy** — create a file in `src/analyzers/`, export a function that returns `{ findings: [] }`, and wire it up in `src/index.js`.\n\n--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------\n\n<div align=\"center\">\n\n**If lockcheck helped you, give it a ⭐ — it helps others find it!**\n\n*Built with zero dependencies.*\n\n</div>\n","readmeFilename":"README.md"}