n8n

@stencil/core

15ee0512-7efd-5a0e-83eb-b2e64d19a0b9 | v4.45.1
67/ 100
HIGH risk
No change since v4.45.0
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (67/100) still counts them.

Analysis record

Analysed
1 weeks ago
Version
v4.45.1
Artifact
SHA256 1D7…36F
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHsupply chain sourcemap appended iife 1
compiler/stencil.js
-

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
supply chain sourcemap appended iife

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality weak.

@stencil/core compiles web components and progressive web apps. The package contains exactly one finding. A high-severity YARA malware-signature match titled YARA--supply_chain_sourcemap_appended_iife sits in /tmp/extract-74c17c70bc39a0ad49bbd2929a20efab6cb8832d839815d1258e3daa404da547-1369180265/compiler/stencil.js. The rule name describes a sourcemap comment appended to an immediately-invoked function expression. Compiled and minified JavaScript bundles routinely contain this pattern. The file path points to the package's own compiler output. No third-party dependency is involved, and the match remains isolated.

No tool-poisoning patterns matched. The scan found no hidden AI directives, no invisible Unicode, no instruction tags in tool descriptions, and no tool definitions that steer an agent.

Stencil operates as a build-time compiler. The tool-poisoning threat model does not apply to its runtime behavior.

The package shows no credential-access findings. It never reads .ssh, .aws, .kube, or environment variables for secrets. Network findings are also absent. Without network activity, credential harvesting cannot combine with exfiltration to an unknown domain. The scan returned no obfuscation findings. It also returned no secret findings and no code-smell findings.

The strongest counterargument rests on the YARA rule's high severity and the word supply_chain in its name. A reader can interpret that as appended malicious code after a sourcemap. The rule matches a single file in the compiler's own output. The pattern sourcemap_appended_iife is a known false-positive signature for legitimate bundled JavaScript. No accompanying IoC, network, or credential evidence supports a supply-chain compromise. The package publishes under the well-known @stencil/core name, and the developer field lists GitHub Actions, consistent with the official Stencil project. A single YARA match in a compiled file, with zero supporting indicators, does not demonstrate malicious behavior.

Key Reasons

  • Single YARA malware-signature finding in compiler/stencil.js is consistent with bundled compiler output
  • No tool-poisoning patterns matched
  • No credential-access or network findings
  • No obfuscation or secret findings
  • Package is a well-known web component compiler

False Positive Considerations

  • YARA supply_chain_sourcemap_appended_iife rule matches compiled bundle output
  • No tool-poisoning, network, or credential findings
  • Known legitimate package @stencil/core

Reviewed 2026-09-06; recommended action: suppress false positive; model confidence 85%.

n8n version history

Risk trend by version

5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
67
Change since first
No change
Change from previous
No change
Versions:
First analyzed version
4.44.0
Aug 11, 2026
Risk range
67 to 67
Across analyzed versions
Latest analyzed version
4.45.1
Sep 23, 2026
Selected version
high
Version
v4.45.1
1 weeks ago
Risk score
67
Findings
1
Change vs previous
No change

Pick any point on the chart to explore that version's code below.

About This Extension

A Compiler for Web Components and Progressive Web Apps

Frequently Asked Questions