Another way to mitigate this attack is to only let trusted sources update the package-lock.json (๐ @greenkeeperio). https://snyk.io/blog/why-npm-lockfiles-can-be-a-security-blindspot-for-injecting-malicious-modules/