PatchSiren

BeProduct CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL BeProduct CVE published 2026-07-20

CVE-2026-46412

A malicious version of the @beproduct/nestjs-auth npm package was published, containing a postinstall payload that attempted to harvest sensitive information. Users who installed versions between 0.1.2 and 0.1.19 should remove the package, clean the npm cache, and install the clean version 0.1.20. This incident highlights the importance of secure package management and vigilant monitoring for potential compromises.