MAL-2026-13408

    Dashboard / Malicious Package / MAL-2026-13408

    MAL-2026-13408

    Published: 6 Aug 2026Last Modified: 6 Aug 2026

    Summary: Malicious code in @activepieces/piece-base44 (npm)

    Details: Source: amazon-inspector (183bc897806f97f30cf26098efd5714de47475d007a7d5e23fe8fb05dbfe9df7) src/index.js requires child_process and issues a ping command at line 16, with multiple POST calls at lines 13, 14, and 29 to hardcoded destinations. The pattern combines OS-level command execution with outbound HTTP POSTs from the module's top level, which is the shape of a reconnaissance and exfiltration payload rather than the piece-integration surface the package name advertises. The base44 name and the @activepieces scope also do not correspond to a known, established Activepieces piece package family, and this version's shipped code performs network I/O beyond what a normal Activepieces piece definition requires.

    Affected packages

    Package

    Name: @activepieces/piece-base44

    Purl: pkg:npm/%40activepieces/piece-base44

    Affected ranges

    Type: N/A

    Events:

    Introduced- None
    Fixed -None

    Affected versions

    0.1.7
    MAL-2026-13408 | CVE-DB