CVE Explorer
CVE-2026-46412
@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The postinstall payload attempted to harvest npm tokens (from `~/.npmrc`); GitHub personal access tokens, OAuth tokens (`gho_*`), and Actions OIDC tokens; AWS credentials (from environment variables
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"beproduct-org-nestjs-auth","vendor":"BeProduct","versions":[{"status":"affected","version":">= 0.1.2, <= 0.1.19"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:fc5af5231e62a5b3c039a98a7403f299008b861fc9c889d9ea80b1d9c92d27fa · sha256:d735a3a77fbd5111… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:fc5af5231e62a5b3c039a98a7403f299008b861fc9c889d9ea80b1d9c92d27fa · sha256:d735a3a77fbd5111… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-506","description":"CWE-506: Embedded Malicious Code","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fc5af5231e62a5b3c039a98a7403f299008b861fc9c889d9ea80b1d9c92d27fa · sha256:d735a3a77fbd5111… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/BeProduct/beproduct-org-nestjs-auth/security/advisories/GHSA-6xwp-cp5h-q856","tags":["x_refsource_CONFIRM"],"url":"https://github.com/BeProduct/beproduct-org-nestjs-auth/security/advisories/GHSA-6xwp-cp5h-q856"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fc5af5231e62a5b3c039a98a7403f299008b861fc9c889d9ea80b1d9c92d27fa · sha256:d735a3a77fbd5111… · /containers/cna/references/0
{"name":"https://www.aikido.dev/blog/checklist-github-actions","tags":["x_refsource_MISC"],"url":"https://www.aikido.dev/blog/checklist-github-actions"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fc5af5231e62a5b3c039a98a7403f299008b861fc9c889d9ea80b1d9c92d27fa · sha256:d735a3a77fbd5111… · /containers/cna/references/1
{"name":"https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised","tags":["x_refsource_MISC"],"url":"https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fc5af5231e62a5b3c039a98a7403f299008b861fc9c889d9ea80b1d9c92d27fa · sha256:d735a3a77fbd5111… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.