Supply ChainMar 11, 2026
UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours
Threat actor UNC6426 exploited stolen credentials from the nx npm package supply chain compromise to gain AWS admin access and breach a victim's cloud environment within 72 hours. The attack chain involved theft of a developer's GitHub token, which was leveraged to access cloud infrastructure and exfiltrate data.
Summary
Threat actor UNC6426 exploited stolen credentials from the nx npm package supply chain compromise to gain AWS admin access and breach a victim's cloud environment within 72 hours. The attack chain involved theft of a developer's GitHub token, which was leveraged to access cloud infrastructure and exfiltrate data.
Indicators of Compromise
- malware — UNC6426
- malware — nx npm package