A package's metadata document, called a packument, lists every version with its dependencies, its tarball URL and its integrity hash. Installers ask for an abbreviated form, which omits READMEs and other fields they never use, by sending a special Accept header.
R=https://registry.npmjs.org
curl -s $R/express -o full.json -w 'full packument: %{size_download} bytes\n'
curl -s -H 'Accept: application/vnd.npm.install-v1+json' $R/express -o abbr.json \
-w 'abbreviated: %{size_download} bytes\n'
jq -r 'keys | join(" ")' abbr.json
jq -r '.versions["5.2.1"].dist | .tarball, .integrity' abbr.jsonfull packument: 808982 bytes abbreviated: 341170 bytes dist-tags modified name versions https://registry.npmjs.org/express/-/express-5.2.1.tgz sha512-hIS4idWWai69NezIdRt2xFVofaF4j+6INOpJlVOLDO8zXGpUVEVzIYk12UUi2JzjEzWL3IOAxcTubgz9Po0yXw==
The abbreviated packument is 42% of the full one, with four keys: dist-tags maps names such as latest to versions, and versions feeds the range matching of Graphs and Semver Ranges. The tarball URL and sha512 integrity value are what your lockfile copies. A CDN caches responses for up to five minutes (max-age=300), so a version you just published can take a moment to appear.
A mirror answers the same URLs from another host: registry.npmmirror.com syncs from npmjs for developers in China, and proxies such as Verdaccio, Sonatype Nexus and JFrog Artifactory cache what your builds download. Select one with the registry setting. Every tarball is checked against the lockfile's hash, so a mirror cannot substitute a tampered file without the install failing.