{"success":true,"data":{"id":"package-lock-integrity-drift","label":"Spoofed CI-bot / npm-security advisory claiming package-lock.json integrity hashes have \"drifted\" from expected checksums. Lures the developer to regenerate the lockfile via a malicious npx command or an attacker-controlled \"lockfile integrity validator\" link. Real Dependabot / Renovate lockfile updates arrive as automated PRs from canonical domains — never as inbound email demanding a manual CLI action on a deadline. Sender NOT on the CI-publisher canonical allowlist (github.com, npmjs.com, renovatebot.com, dependabot.com, etc.). Source: Red-Team R8 multi-agent council C4 (supply-chain specialist).","description":"Spoofed CI-bot or npm-security advisory claiming package-lock.json integrity hashes have \"drifted\" from expected checksums. Lures the developer to regenerate the lockfile via a malicious `npx` command or an attacker-controlled \"lockfile integrity validator\" link within a deadline. Real Dependabot / Renovate lockfile updates arrive as automated PRs from their canonical domains (github.com, renovatebot.com, dependabot.com, npmjs.com) — never as inbound email demanding a manual CLI action on a deadline. Supply-chain attack vector: attacker-controlled lockfile validator script → npm install --package-lock-only overwrites lockfile with attacker-chosen package hashes → compromised packages pulled on next CI run. Sender NOT on the CI-publisher canonical allowlist. Source: Red-Team R8 multi-agent council C4 (supply-chain specialist).","tier":"warning","category":"other","isThin":false}}