Preserve before reinstalling.Path, size, timestamp, hash, stack, executable, version, and installation channel distinguish package corruption from an external writer.

Locate every malformed manifest.

Global install

Scan the selected DSH closure.

npx

Scan the exact execution cache path.

Profile

Scan the selected profile dependencies.

Source

Separate tracked files from generated installs.

Do not replace a broken manifest with {}.

Name, version, exports, dependencies, module type, and native-install contracts are executable package metadata.

Replace the owning closure.

One clean probeexact version · new cache

Prove the artifact before touching production.

One repair ownernpm · profile · Git

Use the channel that owns the bad path.

Repeated corruptionDLP · endpoint · storage

Repair the external mutation boundary first.

Twelve acceptance gates.

Evidence

All bad paths and hashes retained.

Integrity

Repaired scan reports zero failures.

Runtime

Boot, config, turn, and tool pass.

Durability

Cold restart stays clean.

Primary evidence.

Keep the complete recovery runbook.

The canonical guide includes a read-only recursive scanner, install-owner matrix, exact-version probe, npm/npx/profile/source recovery, unsafe shortcuts, twelve gates, and an upstream diagnostic contract.

Read the complete runbook