CVE-2026-46412Patch

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth` (0.1.2 through 0.1.19). The postinstall payload attempted to harvest npm tokens (from `~/.npmrc`); GitHub personal access tokens, OAuth tokens (`gho_*`), and Actions OIDC tokens; AWS credentials (from environment variables and `~/.aws/credentials`); HashiCorp Vault tokens; and other secrets present in environment variables. Version `0.1.20` is a clean republish from the original `0.1.1` source tree. Anyone who installed any version in the range `>=0.1.2 <=0.1.19` should remove the package and clean the npm cache; install the clean version; rotate every credential present in the install environment, including all npm publish tokens, all GitHub PATs and OAuth tokens, AWS access keys, HashiCorp Vault tokens, and any other secret that was in env vars or config files at install time; scan affected hosts for indicators of compromise and, if any are found, treat the host as compromised and reimage; and check committed repository history for unexpected additions in `.claude/` or `.vscode/` directories. The worm is known to commit `setup.mjs` + hook configs to PR branches via automated agent runtimes.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-20); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-21: 1Mentions · 2026-07-20: 2Mentions · 2026-07-23: 1Active Exploitation · 2026-07-23: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-21: 105-2107-2007-23
Signal classification4 categories
Patch
125.0%
Disclosure
125.0%
General
125.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-211
Patch1
2026-07-202
Disclosure1General1
2026-07-231
Active Exploitation1
Full discourse4 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Active Exploitation

    CVE-2026-46412 @beproduct/nestjs-auth A compromised OpenID Connect npm package used malicious postinstall scripts to harvest developer and CI/CD credentials Full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-07-20/TIER_2_CVE-2026-46412.md #CyberSecurity #IdentitySecurity #VulnerabilityManagement

    Post summary

    The post indicates that CVE‑2026‑46412 involves a compromised npm package whose postinstall scripts actively harvest credentials, with a full analysis linked on GitHub, but no PoC, exploit code, patch, or technical details are provided.

    0001037
    59 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerability about mini #Shai-Hulud campaign in #npm packages CVE-2026-46412 CVSS: 10.0 Update @beproduct/nestjs-auth to version 0.1.20 or later, as all previous versions contain malicious code with worm-based payloads #Patch #Patch #Patch

    Post summary

    The post alerts to CVE-2026-46412 in @beproduct/nestjs-auth, noting a CVSS 10.0 rating and worm-based malicious payloads, and urges updating to version 0.1.20 or newer.

    01000233
    7.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-46412 @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, … https://www.cve.org/CVERecord?id=CVE-2026-46412 ----- Traducción: CVE-2026-46412 @be… http://infoflow.cloud`

    Post summary

    The post is a simple disclosure of CVE-2026-46412 for a NestJS authentication module, linking to the CVE record but offering no further technical or exploit details.

    0000025
    93 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-46412 @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, … https://www.cve.org/CVERecord?id=CVE-2026-46412

    Post summary

    The text only references CVE-2026-46412 in passing, showing a module name and a link to the CVE record, but provides no substantive technical or operational details.

    00000366
    57.8K followersView on X

Explore more