
In its Cloud Threat Horizons Report (H1 2026), Google identified the threat actor UNC6426 as the group responsible for a swift breach of a victim’s cloud environment. The attack leveraged secrets stolen during the August 2025 Nx npm supply-chain compromise to gain full AWS administrator access in under 72 hours.
Attack Timeline and Methodology
The Role of AI in the Breach
The original Nx compromise, also known as the “s1ngularity” attack, was one of the first to use AI CLI tools. The malware prompted local AI assistants with dangerous flags to bypass security permissions and scan for credentials that UNC6426 later exploited.
Key Remediation Actions
According to security researchers at Wiz and Kaspersky, organizations should take these actions:
#admin #aws #from #hours #how #malware #news #npm #unc6426 #went — News
© Bulletproof Servers. All rights reserved.