CVE-2026-46412 represents a critical supply chain attack vector involving the @beproduct/nestjs-auth authentication module for BeProduct IDS. Between 2026-05-11 20:19 UTC and 22:56 UTC, threat actors exploited a compromised npm publish token to release versions 0.1.2 through 0.1.19 containing malicious postinstall scripts. These scripts exfiltrated sensitive credentials including npm authentication tokens from ~/.npmrc, GitHub personal access tokens (gho_*) and Actions OIDC tokens, AWS credentials from environment variables and ~/.aws/credentials, HashiCorp Vault tokens, and other environment-based secrets. The vulnerability affects systems utilizing the compromised versions of @beproduct/nestjs-auth, as well as associated platforms including NestJS, npm, BeProduct IDS, and HashiCorp Vault. Given the CVSS 10.0 severity score, immediate action is required: verify installed versions of @beproduct/nestjs-auth, upgrade to the patched version, and rotate all potentially exposed secrets including npm, GitHub, AWS, and Vault credentials.
CRITICAL
CVSS 10.0
CVE-2026-46412
2026-08-12
Critical Vulnerability in @beproduct/nestjs-auth Allows Secret Exfiltration via Malicious npm Packages (CVE-2026-46412)
A critical vulnerability in the @beproduct/nestjs-auth library enabled attackers to publish 18 malicious npm versions between May 11, 2026, 20:19 UTC and 22:56 UTC. The postinstall payload stole npm tokens, GitHub credentials, AWS secrets, and HashiCorp Vault tokens. Immediate remediation required.