
CVE-2026-46412 @beproduct/nestjs-auth A compromised OpenID Connect npm package used malicious postinstall scripts to harvest developer and CI/CD credentials Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-20/TIER_2_CVE-2026-46412.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement
Post summary
The post indicates that CVE‑2026‑46412 involves a compromised npm package whose postinstall scripts actively harvest credentials, with a full analysis linked on GitHub, but no PoC, exploit code, patch, or technical details are provided.



