The AI review rates the findings as likely false positive, but the risk score (67/100) still counts them.
Analysis record
- Analysed
- 3 weeks ago
- Version
- v1.1.414
- Artifact
- SHA256 F88…16D
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | CAP HookExKeylogger | 1 | dist/typeshed-fallback/stubs/pywin32/win32/lib/win32con.pyi | Brian C. Bell -- @biebsmalwareguy FP 5% |
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
Security Analysis: pyright (v1.1.408)
Tool Poisoning Assessment
This package has zero tool-poisoning findings. The findings summary shows tool-poisoning:0, confirming no hidden AI manipulation directives were detected in tool descriptions or metadata. There is no evidence of tool poisoning architecture.
Credential and Network Access
The evidence shows zero credential-access findings and zero network findings. The secret:0 and network:0 counts in the findings summary indicate no code paths reading sensitive credentials or making external HTTP requests. There is no credential exfiltration architecture present.
IoC Findings Analysis
All 1416 IoC findings are false positives from the XIOC extractor misreading JavaScript property access chains as domain names. The finding titles demonstrate this pattern clearly: XIOC-DOMAIN-a.valueexpression.d.strings.map, XIOC-DOMAIN-l.param.name, XIOC-DOMAIN-builtins.int, XIOC-DOMAIN-p.name, and XIOC-DOMAIN-d.shared.name. These are not real domains but property chains like a.valueexpression.d.strings.map being misinterpreted as domain strings. The file path extracted_from_files suggests these came from bundled or extracted content, consistent with the false positive documentation.
Malware Signature
The single malware-signature finding is likely from bundled dependencies or legitimate code patterns triggering broad YARA rules. The malware:0 count indicates no actual malware was detected. This aligns with the known false positive pattern where bundled node_modules trigger multiplicative findings.
Code-Smell Findings
The 2985 code-smell findings are all low-severity and expected for any non-trivial codebase. These are noise from YARA rules matching common JavaScript/Python patterns and do not indicate malicious behavior.
Counterargument
The total finding count of 4402 appears alarming but is entirely explained by documented false positive patterns. The IoC extractor produces massive false positives from property access chains, and code-smell rules fire on almost any non-trivial JavaScript. The absence of tool-poisoning, credential access, and network findings is the critical signal here. pyright is a well-known Python type checker from Microsoft (developer name microsoft1es), and the findings profile matches expected scanner noise rather than malicious behavior.
Key Reasons
- Zero tool-poisoning findings
- Zero credential-access findings
- Zero network findings
- All IoC findings are property chain false positives
- Package is legitimate Microsoft Python type checker
False Positive Considerations
- IoC extractor misreading property access chains as domains
- Code-smell findings from legitimate code patterns
- Malware signature from bundled dependencies
- High finding counts from bundled code
Reviewed 2026-04-27; recommended action: suppress false positive; model confidence 85%.
n8n version history
Risk trend by version
3 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace