Is "@salesforce/pwa-kit-dev" on n8n Safe to Install?

mobify · n8n · v3.17.0

Build tools for pwa-kit

Risk Assessment

Analyzed
75.86
out of 100
HIGH

183 security findings detected across all analyzers

Severity Breakdown

0
Critical
0
High
132
Medium
51
Low
0
Info

Finding Categories

4
Network
125
IoC Indicators

YARA Rules Matched

10 rules(51 hits)
postinstall file download postinstall system command postinstall network communication credential env files postinstall obfuscation postinstall persistence mechanism postinstall crypto operations postinstall file manipulation UsingCommandLineArguments UsingShellInterpreterWhenExecutingOSCommands

About This Extension

Build tools for pwa-kit

Detailed Findings

55 total

YARA Rule Matches

10 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
60
IP Addresses
4
Domains
60
Strings
125

All Indicators · 125

Domain
detected Domain: opensource.org

XIOC detected Domain: opensource.org

extracted_from_files

Domain
detected Domain: process.env.dev

XIOC detected Domain: process.env.dev

extracted_from_files

URL
detected URL: https://test.proxy.com$

XIOC detected URL: https://test.proxy.com$

extracted_from_files

URL
detected URL: https://test.proxy.com').get('/test/path3').reply(200,

XIOC detected URL: https://test.proxy.com').get('/test/path3').reply(200,

extracted_from_files

URL
detected URL: https://example.com',

XIOC detected URL: https://example.com',

extracted_from_files

URL
detected URL: https://cloud.mobify.com',

XIOC detected URL: https://cloud.mobify.com',

extracted_from_files

URL
detected URL: https://cloud.mobify.com/api/projects/project-slug/builds/',

XIOC detected URL: https://cloud.mobify.com/api/projects/project-slug/builds/',

extracted_from_files

URL
detected URL: https://cloud.mobify.com/api/projects/project-slug/builds/target-slug/',

XIOC detected URL: https://cloud.mobify.com/api/projects/project-slug/builds/target-slug/',

extracted_from_files

URL
detected URL: https://cloud.mobify.com/api/projects/project-slug/target/target-slug/jwt/',

XIOC detected URL: https://cloud.mobify.com/api/projects/project-slug/target/target-slug/jwt/',

extracted_from_files

Hash
detected MD5 Hash: A3BBF208965611EC9438D0C1ABD3D990

XIOC detected MD5 Hash: A3BBF208965611EC9438D0C1ABD3D990

extracted_from_files

Hash
detected MD5 Hash: A3BBF207965611EC9438D0C1ABD3D990

XIOC detected MD5 Hash: A3BBF207965611EC9438D0C1ABD3D990

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/overview

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/overview

extracted_from_files

URL
detected URL: https://github.com/SalesforceCommerceCloud/pwa-kit

XIOC detected URL: https://github.com/SalesforceCommerceCloud/pwa-kit

extracted_from_files

URL
detected URL: https://trailhead.salesforce.com/en/content/learn/modules/commerce-pwa-kit-and-managed-runtime

XIOC detected URL: https://trailhead.salesforce.com/en/content/learn/modules/commerce-pwa-kit-and-managed-runtime

extracted_from_files

URL
detected URL: https://cloud.mobify.com';

XIOC detected URL: https://cloud.mobify.com';

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/pushing-and-deploying-bundles.html';

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/pushing-and-deploying-bundles.html';

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/mrt-overview.html#users,-abilities,-and-roles';

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/mrt-overview.html#users,-abilities,-and-roles';

extracted_from_files

URL
detected URL: https://runtime.commercecloud.com/account/settings

XIOC detected URL: https://runtime.commercecloud.com/account/settings

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/

XIOC detected URL: http://ns.adobe.com/xap/1.0/

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/special-components.html

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/special-components.html

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/maximizing-your-cache-hit-ratio.html

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/maximizing-your-cache-hit-ratio.html

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/commerce-api/references?meta=shopper-login:Summary

XIOC detected URL: https://developer.salesforce.com/docs/commerce/commerce-api/references?meta=shopper-login:Summary

extracted_from_files

URL
detected URL: https://developer.salesforce.com/developer-centers/commerce-cloud

XIOC detected URL: https://developer.salesforce.com/developer-centers/commerce-cloud

extracted_from_files

URL
detected URL: https://www.salesforce.com/trailblazerdx/

XIOC detected URL: https://www.salesforce.com/trailblazerdx/

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/retail-react-app.html

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/retail-react-app.html

extracted_from_files

URL
detected URL: https://unpkg.com/@salesforce-ux/[email protected]/assets/fonts/webfonts/SalesforceSans-Bold.woff')

XIOC detected URL: https://unpkg.com/@salesforce-ux/[email protected]/assets/fonts/webfonts/SalesforceSans-Bold.woff')

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

URL
detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

XIOC detected URL: http://www.w3.org/1999/02/22-rdf-syntax-ns#

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/mm/

XIOC detected URL: http://ns.adobe.com/xap/1.0/mm/

extracted_from_files

URL
detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceRef#

XIOC detected URL: http://ns.adobe.com/xap/1.0/sType/ResourceRef#

extracted_from_files

URL
detected URL: https://test.proxy.com').get(targetPath).reply(200,

XIOC detected URL: https://test.proxy.com').get(targetPath).reply(200,

extracted_from_files

Domain
detected Domain: developer.mozilla.org

XIOC detected Domain: developer.mozilla.org

extracted_from_files

IP
detected IP: 0.0.0.0

XIOC detected IP: 0.0.0.0

extracted_from_files

Hash
detected SHA1 Hash: 6d0cfd2308b9f25d8badd722469074889bd3b891

XIOC detected SHA1 Hash: 6d0cfd2308b9f25d8badd722469074889bd3b891

extracted_from_files

URL
detected URL: https://unpkg.com/@salesforce-ux/[email protected]/assets/fonts/webfonts/SalesforceSans-Regular.woff2')

XIOC detected URL: https://unpkg.com/@salesforce-ux/[email protected]/assets/fonts/webfonts/SalesforceSans-Regular.woff2')

extracted_from_files

URL
detected URL: https://unpkg.com/@salesforce-ux/[email protected]/assets/fonts/webfonts/SalesforceSans-Regular.woff')

XIOC detected URL: https://unpkg.com/@salesforce-ux/[email protected]/assets/fonts/webfonts/SalesforceSans-Regular.woff')

extracted_from_files

URL
detected URL: https://unpkg.com/@salesforce-ux/[email protected]/assets/fonts/webfonts/SalesforceSans-Bold.woff2')

XIOC detected URL: https://unpkg.com/@salesforce-ux/[email protected]/assets/fonts/webfonts/SalesforceSans-Bold.woff2')

extracted_from_files

URL
detected URL: https://github.com/SalesforceCommerceCloud/pwa-kit/tree/develop/packages/pwa-kit-dev#readme

XIOC detected URL: https://github.com/SalesforceCommerceCloud/pwa-kit/tree/develop/packages/pwa-kit-dev#readme

extracted_from_files

URL
detected URL: https://github.com/SalesforceCommerceCloud/pwa-kit/issues

XIOC detected URL: https://github.com/SalesforceCommerceCloud/pwa-kit/issues

extracted_from_files

URL
detected URL: https://github.com/SalesforceCommerceCloud/pwa-kit.git

XIOC detected URL: https://github.com/SalesforceCommerceCloud/pwa-kit.git

extracted_from_files

URL
detected URL: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Clear-Site-Data#browser_compatibility');

XIOC detected URL: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Clear-Site-Data#browser_compatibility');

extracted_from_files

URL
detected URL: https://salesforce-internal.slack.com/archives/C8YDDMKFZ/p1677793769255659?thread_ts=1677791840.174309&cid=C8YDDMKFZ

XIOC detected URL: https://salesforce-internal.slack.com/archives/C8YDDMKFZ/p1677793769255659?thread_ts=1677791840.174309&cid=C8YDDMKFZ

extracted_from_files

URL
detected URL: https://test.proxy.com').get('/').reply(301,

XIOC detected URL: https://test.proxy.com').get('/').reply(301,

extracted_from_files

URL
detected URL: https://test.proxy.com').get('/test/path').reply(301,

XIOC detected URL: https://test.proxy.com').get('/test/path').reply(301,

extracted_from_files

URL
detected URL: https://docs.npmjs.com/cli/v8/commands/npm-run-script

XIOC detected URL: https://docs.npmjs.com/cli/v8/commands/npm-run-script

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/upgrade-node-version.html#supported-node-versions

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/upgrade-node-version.html#supported-node-versions

extracted_from_files

URL
detected URL: https://babeljs.io/docs/en/config-files#jest

XIOC detected URL: https://babeljs.io/docs/en/config-files#jest

extracted_from_files

URL
detected URL: https://www.npmjs.com/package/webpack-hot-server-middleware#usage

XIOC detected URL: https://www.npmjs.com/package/webpack-hot-server-middleware#usage

extracted_from_files

URL
detected URL: https://webpack.js.org/configuration

XIOC detected URL: https://webpack.js.org/configuration

extracted_from_files

URL
detected URL: https://salesforce-internal.slack.com/archives/C0DKK1FJS/p1672939909212589

XIOC detected URL: https://salesforce-internal.slack.com/archives/C0DKK1FJS/p1672939909212589

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/pushing-and-deploying-bundles.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/pushing-and-deploying-bundles.html)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/retail-react-app.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/retail-react-app.html)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/rendering.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/rendering.html)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/routing.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/routing.html)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/phased-headless-rollouts.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/phased-headless-rollouts.html)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/launching-your-storefront.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/launching-your-storefront.html)

extracted_from_files

URL
detected URL: https://opensource.org/licenses/BSD-3-Clause

XIOC detected URL: https://opensource.org/licenses/BSD-3-Clause

extracted_from_files

URL
detected URL: https://forms.gle/bUZNxQ3QKUcrjhV18)

XIOC detected URL: https://forms.gle/bUZNxQ3QKUcrjhV18)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/overview)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/overview)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/getting-started.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/getting-started.html)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/skills-for-success.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/skills-for-success.html)

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/configuration-options.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/configuration-options.html)

extracted_from_files

URL
detected URL: https://test.proxy.com');

XIOC detected URL: https://test.proxy.com');

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/proxying-requests.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/proxying-requests.html)

extracted_from_files

URL
detected Domain: url.host

XIOC detected Domain: url.host

extracted_from_files

Domain
detected Domain: groups.id

XIOC detected Domain: groups.id

extracted_from_files

Domain
detected Domain: pkgjson.name

XIOC detected Domain: pkgjson.name

extracted_from_files

Domain
detected Domain: mobify--example.com

XIOC detected Domain: mobify--example.com

extracted_from_files

Domain
detected Domain: bundle.data

XIOC detected Domain: bundle.data

extracted_from_files

Domain
detected Domain: files.map

XIOC detected Domain: files.map

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

Domain
detected Domain: trailhead.salesforce.com

XIOC detected Domain: trailhead.salesforce.com

extracted_from_files

Domain
detected Domain: cloud.mobify.com

XIOC detected Domain: cloud.mobify.com

extracted_from_files

Domain
detected Domain: entries.map

XIOC detected Domain: entries.map

extracted_from_files

Domain
detected Domain: entry.name

XIOC detected Domain: entry.name

extracted_from_files

Domain
detected Domain: semver.default.lt

XIOC detected Domain: semver.default.lt

extracted_from_files

Domain
detected Domain: error.docs

XIOC detected Domain: error.docs

extracted_from_files

Domain
detected Domain: archive.directory

XIOC detected Domain: archive.directory

extracted_from_files

Domain
detected Domain: env.dev

XIOC detected Domain: env.dev

extracted_from_files

Domain
detected Domain: example.com

XIOC detected Domain: example.com

extracted_from_files

Domain
detected Domain: headers.host

XIOC detected Domain: headers.host

extracted_from_files

Domain
detected Domain: unpkg.com

XIOC detected Domain: unpkg.com

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

Domain
detected Domain: ns.adobe.com

XIOC detected Domain: ns.adobe.com

extracted_from_files

Domain
detected Domain: www.salesforce.com

XIOC detected Domain: www.salesforce.com

extracted_from_files

Domain
detected Domain: worker.js.map

XIOC detected Domain: worker.js.map

extracted_from_files

Domain
detected Domain: js.map

XIOC detected Domain: js.map

extracted_from_files

Domain
detected Domain: child.name

XIOC detected Domain: child.name

extracted_from_files

Domain
detected Domain: main.js.map

XIOC detected Domain: main.js.map

extracted_from_files

Domain
detected Domain: ssr.js.map

XIOC detected Domain: ssr.js.map

extracted_from_files

Domain
detected Domain: test.proxy.com

XIOC detected Domain: test.proxy.com

extracted_from_files

Domain
detected Domain: constants.no

XIOC detected Domain: constants.no

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Domain
detected Domain: developer.salesforce.com

XIOC detected Domain: developer.salesforce.com

extracted_from_files

Domain
detected Domain: docs.npmjs.com

XIOC detected Domain: docs.npmjs.com

extracted_from_files

Domain
detected Domain: cnf.name

XIOC detected Domain: cnf.name

extracted_from_files

Domain
detected Domain: compiler.name

XIOC detected Domain: compiler.name

extracted_from_files

Domain
detected Domain: req.app

XIOC detected Domain: req.app

extracted_from_files

Domain
detected Domain: rule.id

XIOC detected Domain: rule.id

extracted_from_files

Domain
detected Domain: matc.call

XIOC detected Domain: matc.call

extracted_from_files

Domain
detected Domain: pkg.name

XIOC detected Domain: pkg.name

extracted_from_files

Domain
detected Domain: starts.call

XIOC detected Domain: starts.call

extracted_from_files

Domain
detected Domain: this.constructor.name

XIOC detected Domain: this.constructor.name

extracted_from_files

Domain
detected Domain: testcase.name

XIOC detected Domain: testcase.name

extracted_from_files

Domain
detected Domain: filter.call

XIOC detected Domain: filter.call

extracted_from_files

Domain
detected Domain: babeljs.io

XIOC detected Domain: babeljs.io

extracted_from_files

Domain
detected Domain: www.npmjs.com

XIOC detected Domain: www.npmjs.com

extracted_from_files

Domain
detected Domain: webpack.js.org

XIOC detected Domain: webpack.js.org

extracted_from_files

Domain
detected Domain: salesforce-internal.slack.com

XIOC detected Domain: salesforce-internal.slack.com

extracted_from_files

Domain
detected Domain: hasownproperty.call

XIOC detected Domain: hasownproperty.call

extracted_from_files

Domain
detected Domain: process.env.ci

XIOC detected Domain: process.env.ci

extracted_from_files

Domain
detected Domain: dedupe.map

XIOC detected Domain: dedupe.map

extracted_from_files

Domain
detected Domain: runtime.commercecloud.com

XIOC detected Domain: runtime.commercecloud.com

extracted_from_files

Domain
detected Domain: projectpkg.name

XIOC detected Domain: projectpkg.name

extracted_from_files

URL
detected Domain: url.search

XIOC detected Domain: url.search

extracted_from_files

Domain
detected Domain: ws.ping

XIOC detected Domain: ws.ping

extracted_from_files

Domain
detected Domain: chalk.green

XIOC detected Domain: chalk.green

extracted_from_files

Domain
detected Domain: program.help

XIOC detected Domain: program.help

extracted_from_files

Domain
detected Domain: e.call

XIOC detected Domain: e.call

extracted_from_files

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

Domain
detected Domain: salesforce.com

XIOC detected Domain: salesforce.com

extracted_from_files

Domain
detected Domain: forms.gle

XIOC detected Domain: forms.gle

extracted_from_files

Domain
detected Domain: changelog.md

XIOC detected Domain: changelog.md

extracted_from_files

URL
detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/setting-up-api-access.html)

XIOC detected URL: https://developer.salesforce.com/docs/commerce/pwa-kit-managed-runtime/guide/setting-up-api-access.html)

extracted_from_files

Security Analysis Summary

Security Analysis Overview

@salesforce/pwa-kit-dev is a n8n extension published by mobify. Version 3.17.0 has been analyzed by the Risky Plugins security platform, receiving a risk score of 75.86/100 (HIGH risk) based on 183 security findings.

Risk Assessment

This extension presents high security risk. Significant concerns were identified during analysis. It is not recommended for use in sensitive or production environments without thorough review.

Findings Breakdown

  • Medium: 132 finding(s)
  • Low: 51 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

@salesforce/pwa-kit-dev is published by mobify on the n8n marketplace.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions