Malicious Package Version Exploit in BeProduct's NestJS Authentication Module
CVE-2026-46412

10CRITICAL

Key Information:

Vendor

Beproduct

Vendor
CVE Published:
20 July 2026

What is CVE-2026-46412?

Between May 11, 2026, an attacker exploited a compromised npm publish token to distribute 18 malicious versions of the @beproduct/nestjs-auth package. These rogue versions contained a post-install payload designed to harvest sensitive credentials, including npm tokens, AWS keys, GitHub personal access tokens, and other environmental secrets. Users who installed any version from 0.1.2 to 0.1.19 must take immediate action to remove the package, clean their npm cache, and rotate all credentials that may have been affected. Additionally, it is crucial to monitor hosts for signs of compromise, particularly looking at specific directories in version control for suspicious changes.

Affected Version(s)

beproduct-org-nestjs-auth >= 0.1.2, <= 0.1.19

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.