Critical
nvd
·
CVE-2026-46412
CVE-2026-46412: @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support
Published Jul 20, 2026
CVSS 10.0
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of @beproduct/nestjs-auth (0.1.2 through 0.1.19). The postinstall payload attempted to harvest npm tokens (from ~/.npmrc); GitHub personal access tokens, OAuth tokens (gho_*), and Actions OIDC tokens; AWS credentials (from environment variables and ~/.aws/credentials); HashiCorp Vault tokens; and other secrets present in environment variables. Version 0.1.20 is a clean republish from the original 0.1.1 source tree. Anyone who installed any version in the range `>=0.1.2
Affected AI Products
claude