n8n

pyright

c1b8d2b9-12c7-5de3-a291-0a3fd4a04894 | v1.1.414
67/ 100
HIGH risk
+33 since v1.1.411
Analyst verdict
Review before use

The AI review rates the findings as likely false positive, but the risk score (67/100) still counts them.

Analysis record

Analysed
3 weeks ago
Version
v1.1.414
Artifact
SHA256 F88…16D
Source
Findings (non-IoC)

Evidence ledger

Ranked by severity · findings with a source location link to the code viewer

1 detail row

YARA Rule Matches

1 rule
SeverityRuleHitsFilesMetadata
HIGHCAP HookExKeylogger 1
dist/typeshed-fallback/stubs/pywin32/win32/lib/win32con.pyi
Brian C. Bell -- @biebsmalwareguy FP 5%

Finding Categories

1
Malware Signatures

YARA Rules Matched

1 rule
CAP HookExKeylogger

AI Security Report

AI Security Review

Evidence context: threat category none; evidence quality strong.

Security Analysis: pyright (v1.1.408)

Tool Poisoning Assessment

This package has zero tool-poisoning findings. The findings summary shows tool-poisoning:0, confirming no hidden AI manipulation directives were detected in tool descriptions or metadata. There is no evidence of tool poisoning architecture.

Credential and Network Access

The evidence shows zero credential-access findings and zero network findings. The secret:0 and network:0 counts in the findings summary indicate no code paths reading sensitive credentials or making external HTTP requests. There is no credential exfiltration architecture present.

IoC Findings Analysis

All 1416 IoC findings are false positives from the XIOC extractor misreading JavaScript property access chains as domain names. The finding titles demonstrate this pattern clearly: XIOC-DOMAIN-a.valueexpression.d.strings.map, XIOC-DOMAIN-l.param.name, XIOC-DOMAIN-builtins.int, XIOC-DOMAIN-p.name, and XIOC-DOMAIN-d.shared.name. These are not real domains but property chains like a.valueexpression.d.strings.map being misinterpreted as domain strings. The file path extracted_from_files suggests these came from bundled or extracted content, consistent with the false positive documentation.

Malware Signature

The single malware-signature finding is likely from bundled dependencies or legitimate code patterns triggering broad YARA rules. The malware:0 count indicates no actual malware was detected. This aligns with the known false positive pattern where bundled node_modules trigger multiplicative findings.

Code-Smell Findings

The 2985 code-smell findings are all low-severity and expected for any non-trivial codebase. These are noise from YARA rules matching common JavaScript/Python patterns and do not indicate malicious behavior.

Counterargument

The total finding count of 4402 appears alarming but is entirely explained by documented false positive patterns. The IoC extractor produces massive false positives from property access chains, and code-smell rules fire on almost any non-trivial JavaScript. The absence of tool-poisoning, credential access, and network findings is the critical signal here. pyright is a well-known Python type checker from Microsoft (developer name microsoft1es), and the findings profile matches expected scanner noise rather than malicious behavior.

Key Reasons

  • Zero tool-poisoning findings
  • Zero credential-access findings
  • Zero network findings
  • All IoC findings are property chain false positives
  • Package is legitimate Microsoft Python type checker

False Positive Considerations

  • IoC extractor misreading property access chains as domains
  • Code-smell findings from legitimate code patterns
  • Malware signature from bundled dependencies
  • High finding counts from bundled code

Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.

n8n version history

Risk trend by version

3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.

Selected
67
Change since first
-2
Change from previous
+33
Versions:
First analyzed version
1.1.408
Mar 9, 2026
Risk range
34 to 70
Across analyzed versions
Latest analyzed version
1.1.414
Sep 10, 2026
Selected version
high
Version
v1.1.414
3 weeks ago
Risk score
67
Findings
1
Change vs previous
+33

Pick any point on the chart to explore that version's code below.

About This Extension

Type checker for the Python language

Frequently Asked Questions