GHSA-6xwp-cp5h-q856
CRITICALCVE-2026-46412Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of @beproduct/nestjs-auth (0.1.2 through 0.1.19). The packages contained payloads from the Mini Shai-Hulud npm supply-chain worm campaign described by [Aikido Security](https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised).
- Affected
- >=0.1.2, >= 0.1.2, <= 0.1.19
- Fixed in
- not stated
- Weakness
- CWE-506
- Published
- 2026-05-19
- Source
- osv