VulnWatch VulnWatch
← Back to dashboard
Critical nvd · CVE-2026-46412

CVE-2026-46412: @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support

Published Jul 20, 2026 CVSS 10.0

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of @beproduct/nestjs-auth (0.1.2 through 0.1.19). The postinstall payload attempted to harvest npm tokens (from ~/.npmrc); GitHub personal access tokens, OAuth tokens (gho_*), and Actions OIDC tokens; AWS credentials (from environment variables and ~/.aws/credentials); HashiCorp Vault tokens; and other secrets present in environment variables. Version 0.1.20 is a clean republish from the original 0.1.1 source tree. Anyone who installed any version in the range `>=0.1.2

Affected AI Products

claude
Get the weekly digest. Every Monday: top AI security stories of the week. Free.