npm package report

Is @beproduct/nestjs-auth safe?

1 known vulnerability, worst severity CRITICAL.

cvss
10.0

how bad it is if exploited, out of 10

epss
0.80%

chance of exploitation in the next 30 days

xyz score
4.0

CyberXYZ composite, out of 10

fig. 01 — GHSA-6xwp-cp5h-q856, the advisory selected below

// advisories

GHSA-6xwp-cp5h-q856

CRITICALCVE-2026-46412

Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of @beproduct/nestjs-auth (0.1.2 through 0.1.19). The packages contained payloads from the Mini Shai-Hulud npm supply-chain worm campaign described by [Aikido Security](https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised).

Affected
>=0.1.2, >= 0.1.2, <= 0.1.19
Fixed in
not stated
Weakness
CWE-506
Published
2026-05-19
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:43 UTC. The most recent advisory here was published 2026-05-19. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @beproduct/nestjs-auth safe? npm package security report | CyberXYZ