How UNC6426 Went from nx npm Malware to AWS Admin in 72 Hours
Mar 11, 2026 // 12:40 - Niko Dunn


In its Cloud Threat Horizons Report (H1 2026), Google identified the threat actor UNC6426 as the group responsible for a swift breach of a victim’s cloud environment. The attack leveraged secrets stolen during the August 2025 Nx npm supply-chain compromise to gain full AWS administrator access in under 72 hours.

Attack Timeline and Methodology

  • Initial Access: UNC6426 used a developer’s GitHub token exfiltrated during the original Nx compromise to access the victim’s GitHub account.
  • OIDC Abuse: The actor exploited the OpenID Connect (OIDC) trust relationship between GitHub Actions and AWS to assume cloud roles.
  • Privilege Escalation: Once inside, they created a new administrator role within the AWS environment to cement full control.
  • Impact: Within the 72-hour window, the group exfiltrated data from Amazon S3 buckets and performed destructive actions in production environments.

The Role of AI in the Breach

The original Nx compromise, also known as the “s1ngularity” attack, was one of the first to use AI CLI tools. The malware prompted local AI assistants with dangerous flags to bypass security permissions and scan for credentials that UNC6426 later exploited.

Key Remediation Actions

According to security researchers at Wiz and Kaspersky, organizations should take these actions:

  1. Rotate Credentials: Replace all GitHub PATs, npm tokens, and cloud keys.
  2. Audit OIDC Roles: Review OIDC-linked AWS roles for unauthorized changes or overly permissive administrator policies.
  3. Clean Environments: Remove malicious Nx versions and clear local npm caches.

#admin  #aws  #from  #hours  #how  #malware  #news  #npm  #unc6426  #went   —   News