The AI review rates the findings as likely false positive, but the risk score (67/100) still counts them.
Analysis record
- Analysed
- 1 weeks ago
- Version
- v4.45.1
- Artifact
- SHA256 1D7…36F
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | compiler/stencil.js | - |
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality weak.
@stencil/core compiles web components and progressive web apps. The package contains exactly one finding. A high-severity YARA malware-signature match titled YARA--supply_chain_sourcemap_appended_iife sits in /tmp/extract-74c17c70bc39a0ad49bbd2929a20efab6cb8832d839815d1258e3daa404da547-1369180265/compiler/stencil.js. The rule name describes a sourcemap comment appended to an immediately-invoked function expression. Compiled and minified JavaScript bundles routinely contain this pattern. The file path points to the package's own compiler output. No third-party dependency is involved, and the match remains isolated.
No tool-poisoning patterns matched. The scan found no hidden AI directives, no invisible Unicode, no instruction tags in tool descriptions, and no tool definitions that steer an agent.
Stencil operates as a build-time compiler. The tool-poisoning threat model does not apply to its runtime behavior.
The package shows no credential-access findings. It never reads .ssh, .aws, .kube, or environment variables for secrets. Network findings are also absent. Without network activity, credential harvesting cannot combine with exfiltration to an unknown domain. The scan returned no obfuscation findings. It also returned no secret findings and no code-smell findings.
The strongest counterargument rests on the YARA rule's high severity and the word supply_chain in its name. A reader can interpret that as appended malicious code after a sourcemap. The rule matches a single file in the compiler's own output. The pattern sourcemap_appended_iife is a known false-positive signature for legitimate bundled JavaScript. No accompanying IoC, network, or credential evidence supports a supply-chain compromise. The package publishes under the well-known @stencil/core name, and the developer field lists GitHub Actions, consistent with the official Stencil project. A single YARA match in a compiled file, with zero supporting indicators, does not demonstrate malicious behavior.
Key Reasons
- Single YARA malware-signature finding in compiler/stencil.js is consistent with bundled compiler output
- No tool-poisoning patterns matched
- No credential-access or network findings
- No obfuscation or secret findings
- Package is a well-known web component compiler
False Positive Considerations
- YARA supply_chain_sourcemap_appended_iife rule matches compiled bundle output
- No tool-poisoning, network, or credential findings
- Known legitimate package @stencil/core
Reviewed 2026-09-06; recommended action: suppress false positive; model confidence 85%.
n8n version history
Risk trend by version
5 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace