npm manifest squats Node core module names (tokenapp/GHAPPIER stage-4)

This rule detects potentially malicious modifications to package.json files in npm projects or suspicious npm registry telemetry. It flags manifest files containing common obfuscation markers or excessive/unusual dependencies often associated with supply chain attacks, such as crypto, child_process, and common third-party packages frequently used in malicious npm activity.