npm ERR! code EINTEGRITY — sha512 integrity checksum failed
A downloaded package’s hash doesn’t match the integrity value in package-lock.json — a corrupted cache, a changed tarball, or a lockfile from a different registry.
Seen on:
npm
Meaning
npm verifies every tarball against the lockfile’s integrity field. Mismatches come from a corrupted local cache, a registry mirror serving different tarballs, or lockfiles edited/merged incorrectly.
Common causes
- Corrupted npm cache
- Lockfile generated against a different registry/mirror
- Bad merge in package-lock.json
- Proxy modifying downloads
⚡ Quick fix
npm cache verify(ornpm cache clean --force)- Delete node_modules and reinstall with
npm ci - Regenerate the lockfile if it was hand-merged
- Use the same registry for everyone (commit
.npmrc)
Detailed fix by platform
npm
- Clean and reinstall:bash
npm cache verify rm -rf node_modules npm ci
How to diagnose
- Package — Which tarball fails?
- Registry — Same registry as the lockfile?
- Cache — Does a clean cache fix it?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026