MAL-2026-13408
Malicious code in @activepieces/piece-base44 (npm)
Details
--- _-= Per source details. Do not edit below this line.=-_
## Source: amazon-inspector (183bc897806f97f30cf26098efd5714de47475d007a7d5e23fe8fb05dbfe9df7) src/index.js requires child_process and issues a ping command at line 16, with multiple POST calls at lines 13, 14, and 29 to hardcoded destinations. The pattern combines OS-level command execution with outbound HTTP POSTs from the module's top level, which is the shape of a reconnaissance and exfiltration payload rather than the piece-integration surface the package name advertises. The base44 name and the @activepieces scope also do not correspond to a known, established Activepieces piece package family, and this version's shipped code performs network I/O beyond what a normal Activepieces piece definition requires.
Are you affected?
Enter the version of the package you're using.
Affected packages
No fixed version published yet for @activepieces/piece-base44 (npm). Pin to a known-safe version or switch to an alternative.