Skip to content
Use this GitHub action with your project
Add this Action to an existing workflow or create a new one
View on Marketplace

Repository files navigation

πŸ”’ lockcheck

Detect malicious dependency diffs in lock files. Catches supply chain attacks before they catch you.

npm version license GitHub stars zero deps Node.js


Every time you run npm install, your lockfile changes. Nobody reviews those diffs. Attackers exploit this by injecting typosquatted, hijacked, or backdoored packages.

lockcheck scans your package-lock.json, diffs it against a saved snapshot, and flags anything suspicious β€” before it reaches production.

⚑ Quick Start

npx @dhanushnehru/lockcheck

That's it. No install required. No configuration. No dependencies.

πŸ” What It Detects

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ πŸ”’ lockcheck                                       β”‚
β”‚ Supply chain security scanner for lock files       β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

  πŸ”΄ CRITICAL
  ────────────────────────────────────────────────────
  πŸ”΄ ev4l-js @1.0.0
    Possible typosquat of "eval-js" (edit distance 1)
    Levenshtein distance: 1

  πŸ”΄ lodash @4.99.0
    Integrity hash changed without version change!
    This could indicate the package was republished.

  ⚠️  WARNINGS
  ────────────────────────────────────────────────────
  ⚠️  sketchy-lib @1.0.0
    New dependency added: sketchy-lib@1.0.0
    (production dependency)

  ⚠️  sketchy-lib @1.0.0
    Published 2 day(s) ago
    New packages should be reviewed carefully.

  ⚠️  sketchy-lib @1.0.0
    Very low download count: 47 weekly downloads
    Low-download packages are higher risk.

  ⚠️  random-helper @2.0.0
    Has install scripts (preinstall/install/postinstall)
    Install scripts can execute arbitrary code.

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚  πŸ“¦ 847 packages scanned                           β”‚
β”‚  πŸ†• 3 new dependencies                             β”‚
β”‚  β†’ 12 version changes                              β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚  πŸ”΄ 2 critical                                     β”‚
β”‚  ⚠️  4 warning(s)                                  β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ›‘οΈ 6 Security Analyzers

Analyzer What It Catches
New Dependencies Packages added since last scan β€” the primary attack vector
Version Jumps Suspicious semver changes: 4.17.21 β†’ 4.99.0, downgrades
Typosquat Detection Names similar to popular packages: 1odash, reqest, epress
Registry Anomalies Non-standard registries, registry switches, integrity hash changes
Install Scripts Packages with postinstall scripts (primary code execution vector)
Freshness Checks Newly published packages with low downloads (via npm registry API)

πŸ“– Usage

# Scan current directory
npx @dhanushnehru/lockcheck

# Scan a specific project
npx @dhanushnehru/lockcheck ./my-app

# CI/CD mode (JSON output + strict exit codes)
npx @dhanushnehru/lockcheck --json --strict

# Offline mode (skip npm registry checks)
npx @dhanushnehru/lockcheck --no-network

# Show help
npx @dhanushnehru/lockcheck --help

πŸ—οΈ How It Works

  1. Parse β€” Reads your package-lock.json (supports lockfileVersion 1, 2, and 3)
  2. Snapshot β€” Compares against a saved .lockcheck-snapshot.json baseline
  3. Analyze β€” Runs 6 independent security analyzers
  4. Report β€” Outputs findings with severity levels (critical/warning/info)
  5. Exit β€” Returns code 0 (safe) or 1 (issues found) for CI integration

On first run, lockcheck creates a baseline snapshot. On subsequent runs, it diffs against that baseline to detect changes.

πŸ€– GitHub Action

Add lockcheck to your CI pipeline to automatically scan every PR:

# .github/workflows/lockcheck.yml
name: Lockfile Security

on:
  pull_request:
    paths:
      - 'package-lock.json'

jobs:
  lockcheck:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: DhanushNehru/lockcheck@v1
        with:
          strict: true

Or use it directly:

- name: Run lockcheck
  run: npx @dhanushnehru/lockcheck --strict

πŸ”§ Options

Flag Description
--json Output results as JSON for CI/CD pipelines
--strict Exit with code 1 on warnings (not just criticals)
--no-network Skip npm registry API checks (offline mode)
--help, -h Show help message
--version, -v Show version number

πŸ’‘ Exit Codes

Code Meaning
0 No critical issues found
1 Critical issues detected (or warnings in --strict mode)
2 Runtime error (missing lockfile, etc.)

πŸ•΅οΈ Why lockcheck?

The Problem

Supply chain attacks on npm have exploded:

  • Typosquatting β€” Packages named 1odash, angu1ar, reqest that execute malicious code
  • Package hijacking β€” Maintainer accounts get compromised, legit packages get backdoored
  • Dependency confusion β€” Private package names are registered on the public registry
  • Postinstall payloads β€” Malicious code runs immediately on npm install

What Exists Today

  • npm audit only checks known CVEs β€” it doesn't catch zero-day supply chain attacks
  • Lock file diffs are thousands of lines that no human reviews
  • CI pipelines auto-merge Dependabot PRs with zero lockfile inspection

What lockcheck Does Differently

  • Proactive detection β€” Catches suspicious patterns before they become CVEs
  • Zero dependencies β€” Eats its own dogfood. Nothing to get supply-chain attacked through.
  • Snapshot diffing β€” Tracks changes over time instead of point-in-time scanning
  • Smart heuristics β€” Typosquat detection, version jump analysis, registry anomaly detection

πŸ›οΈ Architecture

lockcheck/
β”œβ”€β”€ bin/lockcheck.js          # CLI entry point
β”œβ”€β”€ src/
β”‚   β”œβ”€β”€ index.js              # Scan orchestrator
β”‚   β”œβ”€β”€ parsers/npm.js        # package-lock.json parser
β”‚   β”œβ”€β”€ analyzers/            # 6 independent security analyzers
β”‚   β”œβ”€β”€ reporters/terminal.js # Beautiful terminal output
β”‚   └── utils/                # Colors, semver, levenshtein, registry
β”œβ”€β”€ action.yml                # GitHub Action
└── package.json              # Zero dependencies

🀝 Contributing

Contributions are welcome! See CONTRIBUTING.md for guidelines.

Adding a new analyzer is easy β€” create a file in src/analyzers/, export a function that returns { findings: [] }, and wire it up in src/index.js.


If lockcheck helped you, give it a ⭐ β€” it helps others find it!

Built with zero dependencies.

About

A zero-dependency Node.js CLI tool that scans package-lock.json for suspicious patterns that indicate supply chain attacks.

Topics

Resources

Contributing

Stars

11 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages