Detection-only scanner for npm supply-chain compromise. Searches the workstation for installed packages, lockfile pins, IOC filenames, rogue GitHub workflow files, and suspicious lifecycle scripts that match user-provided lists. All scan inputs (affected `package@version` list, IOC filenames, workflow patterns, lifecycle keywords) are supplied by the user via file path, URL, or stdin. No bundled campaign lists. Reports findings; never modifies, quarantines, or deletes anything.