CRITICAL
BeProduct
CVE published 2026-07-20
CVE-2026-46412
A malicious version of the @beproduct/nestjs-auth npm package was published, containing a postinstall payload that attempted to harvest sensitive information. Users who installed versions between 0.1.2 and 0.1.19 should remove the package, clean the npm cache, and install the clean version 0.1.20. This incident highlights the importance of secure package management and vigilant monitoring for potential compromises.