CVE-2026-46412 represents a critical supply chain attack vector involving the @beproduct/nestjs-auth authentication module for BeProduct IDS. Between 2026-05-11 20:19 UTC and 22:56 UTC, threat actors exploited a compromised npm publish token to release versions 0.1.2 through 0.1.19 containing malicious postinstall scripts. These scripts exfiltrated sensitive credentials including npm authentication tokens from ~/.npmrc, GitHub personal access tokens (gho_*) and Actions OIDC tokens, AWS credentials from environment variables and ~/.aws/credentials, HashiCorp Vault tokens, and other environment-based secrets. The vulnerability affects systems utilizing the compromised versions of @beproduct/nestjs-auth, as well as associated platforms including NestJS, npm, BeProduct IDS, and HashiCorp Vault. Given the CVSS 10.0 severity score, immediate action is required: verify installed versions of @beproduct/nestjs-auth, upgrade to the patched version, and rotate all potentially exposed secrets including npm, GitHub, AWS, and Vault credentials.